The WordPress megahack that wasn’t

The auto-update server had a flaw, now fixed, that would have let anyone add anything to websites, putting 27% of the entire web at risk.
Naked Security – Sophos