It has some security fixes: Limited privilege escalation where a site administrator could deactivate network-wide plugins when running a WordPress network under particular circumstances, disclosed by Jon Cave of our WordPress core security team, and Adam Backstrom. Cross-site scripting vulnerability when making URLs clickable, by Jon Cave. Cross-site scripting vulnerabilities in redirects after posting comments in older browsers, and when filtering URLs. Thanks to Mauro Gentile for responsibly disclosing these issues to the security team. Reproducible: Always
+1
This is a bugtracker, not Google+. If you must, use that vote feature, but don't spam. Thanks.
and for the record I will take care of it today after work
3.3.2 added to CVS.
(In reply to comment #5) > 3.3.2 added to CVS. Thanks, Tim. Please update when 3.3.1 is cleaned out and we will get this closed.
CVE-2012-2404 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2404): wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. CVE-2012-2403 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2403): wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. CVE-2012-2402 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2402): wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors. CVE-2012-2401 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2401): Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content. CVE-2012-2400 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2400): Unspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors. CVE-2012-2399 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2399): Unspecified vulnerability in wp-includes/js/swfupload/swfupload.swf in WordPress before 3.3.2 has unknown impact and attack vectors.
(In reply to comment #6) > Thanks, Tim. Please update when 3.3.1 is cleaned out and we will get this > closed. 3.3.1 has now been removed from the tree.
(In reply to comment #8) > > 3.3.1 has now been removed from the tree. Thanks, Tim. Closing noglsa.