12/03/2013 12:19 PMPosted by TasidaAs others have pointed out, the root issue isn't the addons themselves, but rather people writing small scripts that utilize the addons, and functionality that's allowed by the Blizzard client, but not directly accessible to a user who doesn't know how to work with LUA code.
No. The root issue is that the Blizzard scripting API allows a script to send and trade money (and items) without a hardware event. I guarantee you that Blizzard will change this now. This could happen with auctions, trading, and mail.
From reading this thread, the other major issue is that the WeakAuras addon allows execution of arbitrary LUA scripts. It shouldn't do that...at least not by default. Any security expert will tell you that this is a major hole.