This is practically content free. If there really is a known security hole in WordPress, I for one would like to know what it is, so I can patch my sites. Vague burblings about XSS just don't cut it. After all, it's possible that his site was exploited prior to 2.8.4 and he just noticed the problems (or the attack has just become active) now.