Yeah, I read all that. Just like I read the Feb 19 security advisory saying, "I can't stress the importance of this enough, if you are on x-cart below 3.5.X please please make sure you've done the above," and all of the stuff
Here.
Yet I still see nothing with the latest version of the X-Cart script a few ordinary security precautions can't handle (like renaming your admin dir f.ex. - anyone who hasn't done this already with their VB is just begging for it). I'm working with the 3.5.8 version of X-Cart right now and see no reason to be overly concerned. Most of the flags right now are coming from people who are outright speculating at this point because they don't understand how PHP works (although I do see a few whose hosts don't know how to secure their shared servers).
I do admit the guy who paid for the security upgrade has a valid beef though

.