WordPress 3.0.4 Released

WordPress 3.0.4 is available, this release fixes the following:

  • Fix XSS vulnerabilities in the KSES library: Don’t be case sensitive to attribute names. Handle padded entities when checking for bad protocols. Normalize entities before checking for bad protocols in esc_url(). (r17172)

Changelog