Millions of machines affected by command execution flaw in Exim mail server
arstechnica.com
arstechnica.com
I think the main place I'd worry about this is web hosts using a default cPanel config - if they're not already patched past the vulnerable version then compromise of the whole server may take nothing more than a script on a compromised WordPress site.