Upgraded to [WordPress 2.6.2][2] this morning using the WPAU plugin.

The release fixes a vulnerability in the password complexity which could allow user passwords to be reset by the attacker who can later use mt_rand() to predict the random password.

Upgrade if you allow open registration.

Download [WordPress][3] 2.6.2

[1]: /wp-content/uploads/2008/08/wordpresslogo.jpg) [2]: http://wordpress.org/development/2008/09/wordpress-262/ [3]: http://wordpress.org/download/