<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WP-ContactForm HTML Injection Vulnerability</title>
	<atom:link href="http://blogsecurity.net/wordpress/wp-contactform-html-injection-vulnerability/feed" rel="self" type="application/rss+xml" />
	<link>http://blogsecurity.net/wordpress/wp-contactform-html-injection-vulnerability</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Fri, 12 Mar 2010 11:09:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Michael</title>
		<link>http://blogsecurity.net/wordpress/wp-contactform-html-injection-vulnerability/comment-page-1#comment-6227</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Sat, 22 Dec 2007 17:47:57 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-contactform-html-injection-vulnerability/#comment-6227</guid>
		<description>@mustlive... &quot;And they need to fix these holes.&quot;
Do you have any suggestions as to how I can fix these holes, or do I simply de-activate the plug-in?
More importantly: Is there a safe replacement plug-in?

Happy Christmas, etc.,
Michael</description>
		<content:encoded><![CDATA[<p>@mustlive&#8230; &#8220;And they need to fix these holes.&#8221;<br />
Do you have any suggestions as to how I can fix these holes, or do I simply de-activate the plug-in?<br />
More importantly: Is there a safe replacement plug-in?</p>
<p>Happy Christmas, etc.,<br />
Michael</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DK</title>
		<link>http://blogsecurity.net/wordpress/wp-contactform-html-injection-vulnerability/comment-page-1#comment-6216</link>
		<dc:creator>DK</dc:creator>
		<pubDate>Thu, 20 Dec 2007 18:38:19 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-contactform-html-injection-vulnerability/#comment-6216</guid>
		<description>Mustlive, thanks for the heads up.</description>
		<content:encoded><![CDATA[<p>Mustlive, thanks for the heads up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MustLive</title>
		<link>http://blogsecurity.net/wordpress/wp-contactform-html-injection-vulnerability/comment-page-1#comment-6215</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Thu, 20 Dec 2007 16:58:44 +0000</pubDate>
		<guid isPermaLink="false">http://blogsecurity.net/wordpress/wp-contactform-html-injection-vulnerability/#comment-6215</guid>
		<description>These are vulnerabilities in WP-ContactForm 2.0.7 (and previous 2.x versions). And recently I wrote (http://websecurity.com.ua/1641/) about XSS holes in WP-ContactForm 1.5 alpha (and previous 1.x versions) of the plugin.

So users of both original 1.x version and new 2.x version of the plugin are in risk. And they need to fix these holes.</description>
		<content:encoded><![CDATA[<p>These are vulnerabilities in WP-ContactForm 2.0.7 (and previous 2.x versions). And recently I wrote (<a href="http://websecurity.com.ua/1641/" rel="nofollow">http://websecurity.com.ua/1641/</a>) about XSS holes in WP-ContactForm 1.5 alpha (and previous 1.x versions) of the plugin.</p>
<p>So users of both original 1.x version and new 2.x version of the plugin are in risk. And they need to fix these holes.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

