WordPress fixed a comment flaw that could lead to server code execution if a logged-in administrator opened the page.