See this piece: trac.wordpress.org/search?q=security There is load of exploits in XML-RPC, but you need to be very hardcore to use it and monetize it.
Ah, well its a good thing I updated this morning then. Now for fantastico to update so thousands of non-developer users are not left in the dark.