Matt Mullenweg, has declared the entire 2.1.1 version dangerous as cybercrooks gained user-level access to one of the servers controlling Wordpress.org and altered two files that would allow remote PHP code to be executed.
Users who visit websites running on the same server as the compromised WordPress software are not likely to be at risk, but people running the websites (with WordPress software) and running the servers (controlling WordPress), must block access to theme.php and feed.php.
While, some users might have been affected as there are thousands of WordPress downloads everyday, the good news is that the bad news comes with an alternative, WordPress 2.1.2, a new Version that includes minor updates and entirely verified files. Save yourself from attackers now and upgrade to 2.1.2.
























[...] You all know why: [...]