Jason Cohen, founder of WP Engine, said that some people in the media have “incorrectly and unfairly characterized this as a’security vulnerability” in WordPress. He said that calling the risks associated with the XML-RPC implementation used by WordPress a security issue is a “cruel and unfair twisting of the facts” In a statement sent to a handful of journalists, he said that using the pingback function to launch a DDoS attack is not a security problem, but it isn’t shocking to see them attempt to downplay the security issue.”]

