Upgraded to [WordPress 2.6.2][2] this morning using the WPAU plugin.
The release fixes a vulnerability in the password complexity which could allow user passwords to be reset by the attacker who can later use mt_rand() to predict the random password.
Upgrade if you allow open registration.
Download [WordPress][3] 2.6.2
[1]: /wp-content/uploads/2008/08/wordpresslogo.jpg) [2]: http://wordpress.org/development/2008/09/wordpress-262/ [3]: http://wordpress.org/download/