Flaw in WordPress core remains unpatched since November
If it weren’t for the fact that “Author” privileges are needed for this attack, this bug would be huge. Usually, the WordPress team are very quick to correct flaws that have been pointed out to them. It’s hard to believe that this particular flaw has not been fixed since it was first discovered in November.