Attackers are able to use a security hole in WordPress multi-user version 1.0 and earlier versions to add malicious code to websites. This code can be used to access sensitive information and can be inserted through the Username field using the weblog_id parameter.