The WordPress.org development team has released version 3.0.5 of its open source blogging and publishing platform, a maintenance and security update that addresses two vulnerabilities; these could have allowed a Contributor- or Author-level user to gain further access to the site.
An information disclosure issue has also been fixed that allowed Author-level users to view the contents of posts which they should not be able to see, such as draft and private posts.

WordPress 3.0.5 features the addition of two new security enhancements, the first of which improves the security of plugins which were not properly utilising the platform's security API. The other provides better defence against a vulnerability that was fixed in the previous version. All users are encouraged to upgrade to the latest release as soon as possible.

The link for this article located at H Security is no longer available.