Posted by Christian Sciberras on Apr 29
Just for your (and everyone else's) information, WordPress allows
Administrators to Edit Template code, as you may or may not know, is nothing
but plain PHP code.
Besides, WordPress can be made to upload rogue addons (under this same
role), among many other things malicious Administrators might want to do.
At this point I don't think it makes the least sense to call such a feature
a vulnerability, not because it's not exploitable,…
Source: Re: [Full-disclosure] Code Execution vulnerabilit y ? WordPress




