If you can place a .php file in the plugins directory located here: http://www.techcrunch.com/plugins/
And then if you call the script as per your example, then it appears that plugin is loaded (and evaluated).
Someone else more versed in PHP might want to cast their eyes over the wordpress plugin to see whether I'm right: http://wordpress.org/extend/plugins/wp-super-cache/
But it appears it's a case of globals not being checked prior to use: http://php.net/manual/en/security.globals.php
So at first glance and with limited info... it's a plugin. Not that this surprises me, I still use vBulletin and I spend a lot of time code-reading the plugins for that before I use them. Mostly to make sure they don't do silly things like have SQL inside a loop over potentially lots of items, but also for the obvious security holes.
register_globals is an old one though, should be disabled: http://drupal.org/node/222343
I hope they go for the radical openness option and do a full public post-mortem. A teachable moment like this should not be wasted.
register_globals was known to be a bad idea in 1999 for crying out loud.
There's not even a valid reason to turn that setting on, with legacy not even being an excuse.