In an update on the WordPress security situation, PHP Magazine has a new post pointing to some concerned comments over on the WordPress site.
Some of you have heard about a WordPress security issue (a cross-site scripting vulnerability) announced recently. The devs were made aware of this shortly before the public announcement, and we were already working on fixes before the information was released to the public.
We are disappointed that we were not given the opportunity to release fixes for the problems before the information was made public, as is the usual courtesy in the security community. However, that's water under the bridge at this point.
Expect a WordPress 1.2.1 release soon, which will address these issues. We're including a few other minor bugfixes while we're at it.




