<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>BlogSecurity &#187; WordPress</title>
	<atom:link href="http://blogsecurity.net/category/wordpress/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net</link>
	<description>Always something worth reading...</description>
	<pubDate>Wed, 01 Jul 2009 13:33:37 +0000</pubDate>
	<generator>http://wordpress.org/?v=</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>WordPress Plugin DM Albums 1.9.2 vulnerabilities</title>
		<link>http://blogsecurity.net/wordpress/wordpress-plugin-dm-albums-192-vulnerabilities</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-plugin-dm-albums-192-vulnerabilities#comments</comments>
		<pubDate>Wed, 01 Jul 2009 13:33:37 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[Advisories]]></category>

		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=559</guid>
		<description><![CDATA[DM Albums™ is an inline photo album/gallery plugin that displays high quality images and thumbnails perfectly sized to your blog.
Two vulnerabilities have been made public:
1. Stack released  a &#8220;remote file disclosure vulnerability&#8221; (Low-Medium Risk Level)
2. Septemb0x released a &#8220;remote file include vulnerability&#8221; (Critical Risk Level)
An attacker could use these vulnerabilities to potentially gain full access [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-plugin-dm-albums-192-vulnerabilities/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordPress Plugin Related Sites 2.1 Blind SQL Injection Vulnerability</title>
		<link>http://blogsecurity.net/wordpress/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability#comments</comments>
		<pubDate>Wed, 01 Jul 2009 13:26:07 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[Advisories]]></category>

		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=555</guid>
		<description><![CDATA[A critical vulnerability has been discovered in the WordPress Plugin Related Sites plugin. An exploit is available in the wild and available on Milw0rm, making this attack easier to exploit.
Although, the vulnerability says that version 2.1 is vulnerable. You should assume previous versions are vulnerable as well.
BlogSec have confirmed that the current version (at the [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordPress Install Files Security Risk</title>
		<link>http://blogsecurity.net/wordpress/wordpress-install-files-security-risk</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-install-files-security-risk#comments</comments>
		<pubDate>Fri, 08 May 2009 13:35:32 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[blog]]></category>

		<category><![CDATA[blogs]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=512</guid>
		<description><![CDATA[Jeff Starr over at Perishable Press has discovered a way to hack a WordPress blog in rare cases where the installation files have been left behind and the database is in accessible:

The other day, my server crashed and Perishable Press was unable to connect to the MySQL database. Normally, when WordPress encounters a database error&#8230;
The [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-install-files-security-risk/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordPress MU &lt; 2.7 Cross Site Scripting Vulnerability</title>
		<link>http://blogsecurity.net/wordpress/wordpress-mu-27-cross-site-scripting-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-mu-27-cross-site-scripting-vulnerability#comments</comments>
		<pubDate>Thu, 19 Mar 2009 08:32:08 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[Advisories]]></category>

		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=488</guid>
		<description><![CDATA[Cross Site Scripting Vulnerability
Juan Galiana Lara has released details regarding a vulnerability that affects WordPress MU versions &#60; 2.7.
Version 2.7 is NOT affected according to the advisory. So if you have upgraded to 2.7 you can ignore this advisory.
Vulnerability Details
WordPress MU prior to version 2.7 fails to sanitize the Host header correctly in choose_primary_blog function [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-mu-27-cross-site-scripting-vulnerability/feed</wfw:commentRss>
		</item>
		<item>
		<title>How to Firewall Your WordPress Blog</title>
		<link>http://blogsecurity.net/wordpress/how-to-firewall-your-wordpress-blog</link>
		<comments>http://blogsecurity.net/wordpress/how-to-firewall-your-wordpress-blog#comments</comments>
		<pubDate>Thu, 05 Mar 2009 10:22:56 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[Articles]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[blog security]]></category>

		<category><![CDATA[wordpress security]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=471</guid>
		<description><![CDATA[You already know to use a decent password for your blog, but brute-force or dictionary attacks aren&#8217;t the only attacks used against bloggers.  It&#8217;s much cheaper and faster to exploit software flaws, and that the hackers do.  A programmer&#8217;s oversight may allow a hacker to gain access to your blog to insert spyware, [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/how-to-firewall-your-wordpress-blog/feed</wfw:commentRss>
		</item>
		<item>
		<title>Guvnr 10 Steps to Secure WordPress Video</title>
		<link>http://blogsecurity.net/wordpress/guvnr-10-steps-to-secure-wordpress-video</link>
		<comments>http://blogsecurity.net/wordpress/guvnr-10-steps-to-secure-wordpress-video#comments</comments>
		<pubDate>Tue, 03 Mar 2009 00:29:09 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[wordpress security]]></category>

		<category><![CDATA[wordpress whitepaper]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=460</guid>
		<description><![CDATA[Guvnr has released a really detailed article securing a blog using our WordPress Security Whitepaper (which is due for an update soon). The article is titled, &#34;10 tips to make wordpress hack proof&#34;. Has a nice ring to it.
In addition to this, Guvnr has put together a very cool video which takes one through the [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/guvnr-10-steps-to-secure-wordpress-video/feed</wfw:commentRss>
		</item>
		<item>
		<title>3 Tips to Avoid Dangerous Themes and Plugins</title>
		<link>http://blogsecurity.net/wordpress/3-tips-to-avoid-dangerous-themes-and-plugins</link>
		<comments>http://blogsecurity.net/wordpress/3-tips-to-avoid-dangerous-themes-and-plugins#comments</comments>
		<pubDate>Tue, 10 Feb 2009 02:10:19 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[Articles]]></category>

		<category><![CDATA[Reflections]]></category>

		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=413</guid>
		<description><![CDATA[We all love how easy it is to install plugins and themes but how do we know there is no hidden jack in the box waiting to pop out? Viruses, worms and backdoors could be embedded into any theme or plugin and uploaded to the Internet for public consumption.
Here are three easy to use ideas [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/3-tips-to-avoid-dangerous-themes-and-plugins/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordPress Developer Notes</title>
		<link>http://blogsecurity.net/wordpress/wordpress-developer-notes</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-developer-notes#comments</comments>
		<pubDate>Thu, 05 Feb 2009 22:44:39 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[Articles]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[wp-scanner]]></category>

		<category><![CDATA[wpscanner]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=401</guid>
		<description><![CDATA[Introduction
WordPress scanner is a free online resource that blog administrators can use to provide a measure of their wordpress security level. It is BETA software and is continually being developed.
If you have landed here directly we suggest starting at the wp-scanner launch page.
This page is part of a group of pages discussing various aspects of [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-developer-notes/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordPress Scanner FAQ</title>
		<link>http://blogsecurity.net/wordpress/wpscanner-faq</link>
		<comments>http://blogsecurity.net/wordpress/wpscanner-faq#comments</comments>
		<pubDate>Thu, 05 Feb 2009 22:12:57 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[Articles]]></category>

		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=392</guid>
		<description><![CDATA[Introduction
WordPress scanner is a free online resource that blog administrators can use to provide a measure of their wordpress security level. It is BETA software and is continually being developed.
If you have landed here directly we suggest starting at the wp-scanner launch page.
This page is part of a group of pages discussing various aspects of [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wpscanner-faq/feed</wfw:commentRss>
		</item>
		<item>
		<title>WordPress Scanner Next-Gen Released</title>
		<link>http://blogsecurity.net/wordpress/wordpress-scanner-next-gen-released</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-scanner-next-gen-released#comments</comments>
		<pubDate>Tue, 03 Feb 2009 00:23:37 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[wordpress scanner]]></category>

		<category><![CDATA[wpscan]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=370</guid>
		<description><![CDATA[Here it is!!!
Its been a long and exciting week. Not only are we experiencing the most severe snow in Kent but I&#8217;ve finally managed to role out the massively improved WordPress vulnerability scanner. It can also be accessed using the menu link above, &#8220;WordPress Scanner&#8221;.
It is a complete re-write of the old scanner. I&#8217;ve not [...]]]></description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-scanner-next-gen-released/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
