A security flaw in WordPress versions 2.0 up to 2.0.9 and versions 2.1 up to 2.1.1 allowed an attacker to insert malicious code into a website. This could be done by sending a specially crafted request to the website using the file parameter of the wp-admin/templates.php page