Wordpress 2.1.1 has been tampered by some cracker and contains exploitable code. Everyone on that bandwagon should move to 2.1.2 ASAP to avoid some nasty things from going on with their blogs. Like getting pwnt :)
Is this lax security on the part of WP? Wouldn’t say so. It is an open-source project. Not that it’s inherently insecure, just that when a lot of people could have access, some shithead somewhere will try to gain an edge with his friends. Should it have been caught before it was mass-released? Yes, probably so. But it got caught fast enough I guess so hopefully nobody got screwed over too badly.
I wonder who’s scanning for WP 2.1.1 in the header files right now…












