WordPress has released a security update for version 2.5.1 of the blogging
software. Users that allow open registrations (for user comments or for
multi-author blogs) should update immediately. The update also includes over 70
other fixes for the media uploader, widget administration and layout. WordPress
users can download these corrected copies of
wp-includes/pluggable.php,
wp-admin/includes/media.php,
and
wp-admin/media.php.
Simply replace your existing copies of these files with the new copies and avoid
the inevitable exploitation when the hole is publicly announced.