Robert Deaton wrote:
If you don't upgrade to 2.0.5, you have the vulnerable plugin in your plugins directory. There are still many 2.0.2 blogs out in the wild at this point, and for those who won't upgrade to 2.1, they may still use and still have a vulnerable plugin. Mark it deprecated and recommend the XML export on the plugins panel and on upgrade for all I care, but deleting the plugin from wp-content doesn't make it go away for people who already have it from their last WP upgrade or their most recent install.
That's a pretty good case for leaving it in 2.0.5, thanks for making those points.
-- Matt Mullenweg http://photomatt.net | http://wordpress.org http://automattic.com | http://akismet.com _______________________________________________ wp-testers mailing list [email protected] http://lists.automattic.com/mailman/listinfo/wp-testers
