dear matt, i have experienced a security hole in wordpress 2.6.1.
someone has installed a file called besucher.txt in the root of the blog.
plugins active:
Akismet 2.1.8
Flash Tag Cloud 0.4
Flexo Archives 1.0.12
Get Recent Comments 2.0.2
Highlight Author Comments 1.0.3
ShareThis 2.3
Snazzy Archives 0.5.2
Subscribe To Comments 2.1.2
WP-Cumulus 1.13
WP-DBManager 2.31
WP-PostRatings 1.31
WP-PostRatings Widget 1.31
WP Auto Tagger 1.3.1
WP Super Cache
inactive plugins:
cforms 8.7
WP-chgFontSize 1.6
WP-OpenID 2.2.2
Hello Dolly 1.5
posted on the forum but no replies.
please excuse me for posting here, but i think this could be important.
marco infussi