That did it, thank you - I switched the PHP Support type to FastCGI and created a new wordpress instance and it did not have the globally writable directories. Thank you very much. Out of curiosity, why have the default choice be something that leads to security issues? When I create a new...
Plesk version is 12.0.18 Update #7 running on Centos 6.5. When my customer mentioned that new Wordpress installs were creating unsecure directories I reactivated an old account that was no longer in use, created a wordpress instance through the Plesk Application Manager and saw the same thing...
We recently had several customers running wordpress have their sites violated and used to send out spam. It looks like this was possible because their sites were filled with globally writable/executable directories and the spammer was using php code to send mail using the system mail command...