also wenn der entwickler von spam karma sagt, dass es einen fehler gibt in seinem plugin, dass zur kompromitierung des blogs führen kann über die registrierung, dann ist das für mich glaubwürdig genug.
folgende aussage wurde heute nacht übrigens getätigt von ihm:
Zitat(...)2) no, obviously I cannot give you the slightest amount of detail on the exploit. You’ll have to take my word for it (but don’t feel like you have to). It’s been tested and shown to exist with varying levels of danger on *all* versions of WP up to the very last one.
3) wp devs have been notified. I am *not* an official WP dev. Both this announcement and any technical opinion I may have about it are my very own and not in any way representative of the official WP position, response to it or lack thereof (thanks Cthulhu).
4) it is fairly easy to patch, though Lead seem to have had more important priorities at the moment. However, merely releasing the patch is akin to publicly disclose the exploit. Which *must* be done at some point, but hopefully not before as many regular users as possible have heard the message and protected their blog (I trust the simple act of disabling this option is more likely to be done promptly than an actual upgrade).
5) if looking for any official answer, emergency response deployment, reassurance, dismissal or otherwise Party-sanctionned advices, contact WP officials, not me.
Thanks and happy blogging nonetheless…