<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Rene Schmidt Freelancer &#187; Wordpress Plugin Security</title>
	<atom:link href="http://www.reneschmidt.de/category/work/wordpress-plugin-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.reneschmidt.de</link>
	<description>Berater für Web-Entwicklung und eCommerce</description>
	<lastBuildDate>Thu, 24 Jun 2010 21:17:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>WP Plugin Security: Multiple Leaks in WP-PhotoContest</title>
		<link>http://www.reneschmidt.de/wpphotocontest/</link>
		<comments>http://www.reneschmidt.de/wpphotocontest/#comments</comments>
		<pubDate>Sun, 18 Oct 2009 14:00:32 +0000</pubDate>
		<dc:creator>Rene Schmidt</dc:creator>
				<category><![CDATA[Misc]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Web Development]]></category>
		<category><![CDATA[Wordpress Plugin Security]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[photocontest]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.reneschmidt.de/?p=2268</guid>
		<description><![CDATA[What IS WP PhotoContest? The readme states: This plugin permits you to create a &#8216;voting for photos-contest&#8217; from the WordPress admin panel Subscribed users can uploads photos and everyone else can vote for the uploaded photos (sic). The author could rephrase that as follows: This plugin permits everyone to inject SQL commands into the database [...]]]></description>
		<wfw:commentRss>http://www.reneschmidt.de/wpphotocontest/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WP Plugin Security: When the genius is out for lunch</title>
		<link>http://www.reneschmidt.de/when-the-genius-is-out-for-lunch/</link>
		<comments>http://www.reneschmidt.de/when-the-genius-is-out-for-lunch/#comments</comments>
		<pubDate>Sun, 11 Oct 2009 10:53:21 +0000</pubDate>
		<dc:creator>Rene Schmidt</dc:creator>
				<category><![CDATA[Misc]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Web Development]]></category>
		<category><![CDATA[Wordpress Plugin Security]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[hole]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[swift]]></category>
		<category><![CDATA[theme]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.reneschmidt.de/?p=2222</guid>
		<description><![CDATA[I am in the mood for some more ranting&#8230; Why am I doing this? The low security level in the WordPress community aggravates me. And I care about the security of WordPress users out there. So here goes the next issue.It&#8217;s a rather insignificant XSS security vulnerability but since the WP theme&#8217;s author runs the [...]]]></description>
		<wfw:commentRss>http://www.reneschmidt.de/when-the-genius-is-out-for-lunch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WP Plugin Security: WP Shopping Cart/WP eCommerce Security Holes</title>
		<link>http://www.reneschmidt.de/wpscsecurity/</link>
		<comments>http://www.reneschmidt.de/wpscsecurity/#comments</comments>
		<pubDate>Sat, 10 Oct 2009 14:06:18 +0000</pubDate>
		<dc:creator>Rene Schmidt</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Web Development]]></category>
		<category><![CDATA[Wordpress Plugin Security]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[holes]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[shopping cart]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.reneschmidt.de/?p=2214</guid>
		<description><![CDATA[Another week, another security hole. This time I have found several holes in ajax-and-init.php from WP-eCommerce v3.7.4 aka WP Shopping Cart. It is the latest stable version. Let&#8217;s go. The first issue is an unrestricted file deletion security breach. Remote attackers can trick a logged in WP user to click prepared links that can make [...]]]></description>
		<wfw:commentRss>http://www.reneschmidt.de/wpscsecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WP Plugin Security: WP-Ajax-Edit-Comments</title>
		<link>http://www.reneschmidt.de/wordpress-plugin-quality/</link>
		<comments>http://www.reneschmidt.de/wordpress-plugin-quality/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 13:32:03 +0000</pubDate>
		<dc:creator>Rene Schmidt</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Web Development]]></category>
		<category><![CDATA[Wordpress Plugin Security]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wp ajax edit comments]]></category>

		<guid isPermaLink="false">http://www.reneschmidt.de/?p=2143</guid>
		<description><![CDATA[Security hole in Wordpress plugin WP Ajax Edit Comments up to v2.4.0.1 -- upgrade now]]></description>
		<wfw:commentRss>http://www.reneschmidt.de/wordpress-plugin-quality/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
