WordPress 2.2.1 and WordPress MU 1.2.3 have a security vulnerability that allows people who are logged in to the system to upload and run malicious code. This bug is related to the wp_postmeta table and the use of custom fields in regular posts. It is similar to another security issue (CVE-2007-3543) that was not completely fixed.