The WordPress team released WordPress 2.6.5 earlier today. This release addresses a potential XSS (cross-site scripting) attack under some server configurations, plus adds some bugfixes for some other minor issues. As noted in the official announcement, there was no official 2.6.4 release. There was an attempt to fool people into downloading a fake release under that number, so it has been skipped in the official release numbering, to avoid confusion.
I would like to take this opportunity to point out the WordPress project entry on Freshmeat. [...]












Bug Chasing
Okay, so in my post about Code Spelunking I mentioned about how working on a project can lead you to explore the code because you need to become more familiar with how the code works. But it can also lead you to explore the code to figure out why code doesn’t work. In this particular case, I spent many hours puzzling over why something didn’t work correctly, chasing down the root cause, and eventually finding a bug in the WordPress core. [...]