WordPress 2.1.2 and possibly earlier versions have a security issue which allows remote users who are logged in to run dangerous commands through a string in an XML RPC mt.setPostCategories method call. This could allow them to access and change information in the website’s database.