http://wordpress.org/wordpress-2.8.6-beta1.zip Fixes these two security issues: https://core.trac.wordpress.org/query?status=closed&group=resolution&milestone=2.8.6 A logged in user with author privileges is required to exploit. Press This and uploads need testing.