The XML vulnerability is present in WordPress and Drupal versions from 3.5 to 3.9.1. The vulnerability is a remote procedure call (RPC) protocol which uses XML to encode its request and the HTTP as a carrier. The problem is a problem related to the PHPs XML processor that was promptly fixed by the WordPress security team and the Drupal security team. Both CMSs have released an update today to fix the problem, all users that have chosen to manually update their CMS instance, urge to upgrade it to the latest version.”]
Source: http://securityaffairs.co/wordpress/27409/hacking/drupal-drupal-critical-flaw.html

