WordPress 2.0.2 and earlier versions contain a security issue that allows remote attackers to run malicious code on the system. Attackers can do this by entering a special combination of characters and code into certain parts of a profile when it is updated. The malicious code will be stored in files located in two different folders