There’s yet another small major security bug for WordPress users: Florian Holzhauer explains on how to disable the bug which allows to execute an entire set of PHP or shell commands.

There is an exploit for Wordpress up and including to out in the wild, which works on webservers with enabled register_globals.
The quick fix is to place
in index.php at the very top, right after declaring “php” before any other php statements.

There’s no guarantee and liability for the success or any possible errors caused by this mini-workaround, so the best idea is to use an upcoming WordPress version which corrects the bug.

