WordPress has issued an automatic update to address a critical flaw in theΒ Jetpack pluginΒ thatβs installed on over five million sites.
The vulnerability, which was unearthed during an internal security audit, resides in an API present in the plugin sinceΒ version 2.0, which was released in November 2012.
βThis vulnerability could be used by authors on a site to manipulate any files in the