wordpress.org — 2.2.1 is a bug fix release for the 2.2 series. 2.2.1 addresses the following vulnerabilities: Remote shell injection in PHPMailer, Remote SQL injection in XML-RPC Discovered by Alexander Concha, Unescaped attribute in default theme. Upgrading is recommended.