A security weakness in WordPress version 1.5.2 and possibly earlier versions before 2.0 could allow someone to send malicious code through the User-Agent field in an HTTP header associated with a comment. This malicious code could allow someone to execute instructions that could harm the website.