[possible script injection via /etc/wordpress/wp-config.php]
bigger problems, if attacker has access to /etc/wordpress/*