Forum Moderators: phranque
Unfortunately, 2.2.1 is not just a bug fix release. Some security issues came to light during 2.2.1 development, making 2.2.1 a required upgrade. 2.2.1 addresses the following vulnerabilities:
Remote shell injection in PHPMailer Remote SQL injection in XML-RPC Discovered by Alexander Concha. Unescaped attribute in default theme
That middle one appears to be a worm waiting to happen, chances are you will have your WordPress install taken over if you don't upgrade quickly and you have not removed the xml-rpc file.
Like many, our wordpress installs are too hacked up to be upgraded unfortunately. I've got to go research these bugs and patch manually somehow.
So you have the unfortunate situation that you don't know, and most likely can't easily evaluate, the quality and the security of the code in your chosen theme, and WordPress aren't going to help you.
The phpBB project lost years of development time when repeated security errors forced them to do a complete security audit of their entire codebase. WordPress may need to go down that path too, and slow or stop development until their existing code is up to scratch. Otherwise, confidence in their product is going to be seriously undermined.