File uploads allow for cross-site scripting in Wordpress
nealpoole.com
nealpoole.com
If you have a malicious user with Author permissions, or who has their account compromised, you're in a lot of trouble already. There's an assumption that if a user can be trusted to write posts with arbitrary HTML, the same user can be trusted to upload a variety of files.