<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BlogSecurity &#187; Advisories</title>
	<atom:link href="http://blogsecurity.net/category/wordpress/advisories/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Mon, 22 Feb 2010 21:41:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>WordPress Thrashing Authorisation Bypass</title>
		<link>http://blogsecurity.net/wordpress/wordpress-thrashing-authorisation-bypass</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-thrashing-authorisation-bypass#comments</comments>
		<pubDate>Mon, 22 Feb 2010 21:41:28 +0000</pubDate>
		<dc:creator>Philipp</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=607</guid>
		<description><![CDATA[Thomas Mackenzie has reported a vulnerability affecting Wordpress &#62;= 2.9. Versions before 2.9 are not vulnerable.
tmacuk quote:
Since version 2.9 a new feature was implemented so that users were able to retrieve posts that they may have deleted by accident. This new feature was labelled ‘trash’. Any posts that are placed within the trash are only viewable [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-thrashing-authorisation-bypass/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress Trackback &lt; 2.8.5 Denial of Service</title>
		<link>http://blogsecurity.net/wordpress/wordpress-trackback-2-8-5-denial-of-service</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-trackback-2-8-5-denial-of-service#comments</comments>
		<pubDate>Tue, 12 Jan 2010 22:00:03 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=603</guid>
		<description><![CDATA[If you are running WordPress &#60; 2.8.5 and finding your blog inaccessible at times this post may be for you.
A denial of vulnerability was released back in Oct 2009 that affects &#60; WordPress 2.8.5. 
The exploit sends a continuous stream of POST requests with overly large blog titles to wp-trackback.php. This could result in the [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-trackback-2-8-5-denial-of-service/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Distributed WordPress Password Guessing</title>
		<link>http://blogsecurity.net/wordpress/distributed-wordpress-password-guessing</link>
		<comments>http://blogsecurity.net/wordpress/distributed-wordpress-password-guessing#comments</comments>
		<pubDate>Tue, 08 Dec 2009 23:00:22 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Articles]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=589</guid>
		<description><![CDATA[One of The Internet Storm Center readers recently discovered a malicious WordPress hacking script.
The script is nothing more then a password guessing tool. However, what makes it unique &#8212; as pointed out by ISC, is the fact that it uses a MySQL database backend to store password attempts. This means the script could be executed [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/distributed-wordpress-password-guessing/feed</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>WordPress </title>
		<link>http://blogsecurity.net/wordpress/wordpress-2-8-3-reset-admin-password-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-2-8-3-reset-admin-password-vulnerability#comments</comments>
		<pubDate>Tue, 11 Aug 2009 15:02:50 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=578</guid>
		<description><![CDATA[An exploit has been released for all current versions of WordPress including WordPress ]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-2-8-3-reset-admin-password-vulnerability/feed</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>WordPress 2.8.3 Fixes Security Holes</title>
		<link>http://blogsecurity.net/wordpress/wordpress-2-8-3-fixes-security-holes</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-2-8-3-fixes-security-holes#comments</comments>
		<pubDate>Tue, 04 Aug 2009 21:43:40 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=571</guid>
		<description><![CDATA[If you haven&#8217;t already done so, we&#8217;d stongly recommend upgrading to WordPress 2.8.3. Also, the WordPress 2.0.x branches are now deprecated (a bit earlier then expected) and will therefore no longer be maintained. [Link]
Unfortunately, I missed some places when fixing the privilege escalation issues for 2.8.1.  Luckily, the entire WordPress community has our backs. [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-2-8-3-fixes-security-holes/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress Plugin DM Albums 1.9.2 vulnerabilities</title>
		<link>http://blogsecurity.net/wordpress/wordpress-plugin-dm-albums-192-vulnerabilities</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-plugin-dm-albums-192-vulnerabilities#comments</comments>
		<pubDate>Wed, 01 Jul 2009 13:33:37 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=559</guid>
		<description><![CDATA[DM Albums™ is an inline photo album/gallery plugin that displays high quality images and thumbnails perfectly sized to your blog.
Two vulnerabilities have been made public:
1. Stack released  a &#8220;remote file disclosure vulnerability&#8221; (Low-Medium Risk Level)
2. Septemb0x released a &#8220;remote file include vulnerability&#8221; (Critical Risk Level)
An attacker could use these vulnerabilities to potentially gain full access [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-plugin-dm-albums-192-vulnerabilities/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>WordPress Plugin Related Sites 2.1 Blind SQL Injection Vulnerability</title>
		<link>http://blogsecurity.net/wordpress/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability#comments</comments>
		<pubDate>Wed, 01 Jul 2009 13:26:07 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=555</guid>
		<description><![CDATA[A critical vulnerability has been discovered in the WordPress Plugin Related Sites plugin. An exploit is available in the wild and available on Milw0rm, making this attack easier to exploit.
Although, the vulnerability says that version 2.1 is vulnerable. You should assume previous versions are vulnerable as well.
BlogSec have confirmed that the current version (at the [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>WordPress MU &lt; 2.7 Cross Site Scripting Vulnerability</title>
		<link>http://blogsecurity.net/wordpress/wordpress-mu-27-cross-site-scripting-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-mu-27-cross-site-scripting-vulnerability#comments</comments>
		<pubDate>Thu, 19 Mar 2009 08:32:08 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=488</guid>
		<description><![CDATA[Cross Site Scripting Vulnerability
Juan Galiana Lara has released details regarding a vulnerability that affects WordPress MU versions &#60; 2.7.
Version 2.7 is NOT affected according to the advisory. So if you have upgraded to 2.7 you can ignore this advisory.
Vulnerability Details
WordPress MU prior to version 2.7 fails to sanitize the Host header correctly in choose_primary_blog function [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-mu-27-cross-site-scripting-vulnerability/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Old WP-Forum Vulnerability Gets Disclosed</title>
		<link>http://blogsecurity.net/wordpress/wp-forum-178-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wp-forum-178-vulnerability#comments</comments>
		<pubDate>Tue, 27 Jan 2009 00:14:06 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[BlogWatch]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[wordpress plugin vulnerability]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=335</guid>
		<description><![CDATA[
An vulnerability for  Fredrik Fahlstad&#8217;s WP-Forum Plugin has been made public on milw0rm. The exploit appears to affect an older version (1.7.8) of the popular WordPress plugin.


The plugins homepage is already on version 2.2. This means this vulnerability was probably discovered shortly after the initial version 1.7.4 vulnerability reported by BlogSecurity in early 2008.


As [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wp-forum-178-vulnerability/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WordPress </title>
		<link>http://blogsecurity.net/wordpress/wordpress</link>
		<comments>http://blogsecurity.net/wordpress/wordpress#comments</comments>
		<pubDate>Thu, 08 Jan 2009 14:35:24 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=294</guid>
		<description><![CDATA[
Jeremias Reith has published the advisory to Bugtraq which includes a proof of concept exploit that may allow an unauthenticated attacker access to your blog.


Product affected: WordPress 
Version(s): ]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
