WordPress 2.9.2 was released just a few minutes ago to address a security problem dealing with the Trash feature.
When WordPress implemented the new feature they failed to change the permissions granted when the post is in the trash. This means that an unauthenticated user cannot see the post, however an authenticated user can no matter what privileges they have, even ’subscriber’.
There are probably a few other bug fixes in this version but they were not part of the release announcement. If your site only has one author and no registered users, this upgrade is not critical.
[…] A new WordPress security vulnerability has been discovered, in 2.9 and 2.9.1. It has to do with the newly (and badly) implemented “trash can” feature. (Instead of just deleting posts when told to, WordPress now routes them through a convoluted trash system.) You can read about the new 2.9.2 version over at the WordPress Tavern blog. […]