WordPress versions before 2.0.10 RC2 and 2.1.3 RC2 contain a security vulnerability that allows someone who is remotely logged in with certain privileges to add malicious code to the WordPress website. This malicious code could let them control parts of the website or access private information about visitors.