<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>JaypeeOnline &#187; redoable</title> <atom:link href="http://jaypeeonline.net/tag/redoable/feed/" rel="self" type="application/rss+xml" /><link>http://jaypeeonline.net</link> <description>Technology, Blogging News, WordPress Theme and Plugin Reviews, Tips and Tricks</description> <lastBuildDate>Mon, 21 May 2012 03:17:06 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=</generator> <item><title>Top 10 Vulnerable WP Themes</title><link>http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/</link> <comments>http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/#comments</comments> <pubDate>Fri, 10 Aug 2007 16:23:18 +0000</pubDate> <dc:creator>Jaypee Habaradas</dc:creator> <category><![CDATA[WordPress]]></category> <category><![CDATA[blogsecurity]]></category> <category><![CDATA[cross-site-scripting]]></category> <category><![CDATA[k2]]></category> <category><![CDATA[redoable]]></category> <category><![CDATA[vistered-little]]></category> <category><![CDATA[vulnerable-wordpress-themes]]></category><guid
isPermaLink="false">http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/</guid> <description><![CDATA[BlogSecurity an organization that deals with web blog security recently posted a list of the top 10 WordPress themes that are vulnerable to Cross-Site Scripting due to template flaws. 1. field-of-dreams 2. tarski 3. mandigo-14,1.22 4. connections 5. default 6. freshy 7. redoable 8. k2 9. vistered-little-1.6a 10. wp-multiflex-3 Some of the themes on the [...]]]></description> <content:encoded><![CDATA[<p></p><p><a
href="http://blogsecurity.net/">BlogSecurity</a> an organization that deals with web blog security recently posted a list of the <a
href="http://blogsecurity.net/wordpress/article-050807/">top 10 WordPress themes</a> that are vulnerable to <a
href="http://en.wikipedia.org/wiki/Cross-site_scripting">Cross-Site Scripting</a> due to template flaws.</p><p>1. <a
href="http://www.notsoboringlife.com/the-arts/blogging/wordpress-theme-field-of-dreams/">field-of-dreams</a><br
/> 2. <a
href="http://tarskitheme.com/">tarski</a><br
/> 3. <a
href="http://www.onehertz.com/portfolio/wordpress/mandigo/">mandigo-14,1.22</a><br
/> 4. <a
href="http://vanillamist.com/blog/?page_id=64">connections</a><br
/> 5. default<br
/> 6. <a
href="http://www.jide.fr/english/downloads/template-freshy-wordpress/">freshy</a><br
/> 7. <a
href="http://www.deanjrobinson.com/wordpress/redoable">redoable</a><br
/> 8. <a
href="http://getk2.com/">k2</a><br
/> 9. <a
href="http://windyroad.org/">vistered-little-1.6a</a><br
/> 10. <a
href="http://webgazette.co.uk/web-design/wordpress-themes/wp-multiflex-3/">wp-multiflex-3</a></p><p><span
id="more-368"></span></p><p>Some of the themes on the list are popular WordPress themes, like <strong>freshy</strong>, <strong>k2</strong> and <strong>redoable</strong>. I hope that the theme authors would look into this and make the necessary changes and fix the template flaws.</p><p>If you want to perform the same test for your blog or WordPress themes that you&#8217;ve created, you can use the same method used by BlogSecurity team. All you need to do is follow the installation instructions:</p><ul><li>Download the <a
href="http://blogsecurity.net/projects/wp-scanner.zip">wp-scanner activator</a> plugin.</li><li>Upload the plugin file to your <strong>wp-contents/plugin</strong> folder.</li><li><strong>Activate</strong> the plugin from the admin panel.</li><li><a
href="http://blogsecurity.net/wpscan">Launch the wp-scanner</a> and perform the test.</li><li>As soon as you&#8217;re done, <strong>de-activate</strong> the plugin so other people can&#8217;t to scan your blog.</li></ul><p>Btw, I performed the test for JaypeeOnline and I&#8217;m happy with the result:</p><p><img
src="http://maxcdn.jaypeeonline.net/images/wpscanner_result.jpg" alt="WP Scanner Result for JaypeeOnline" /></p><p>I strongly recommend that you also perform this test so you can find out if the WordPress theme you&#8217;re using is vulnerable or not. It would only take a few minutes of your time. If you&#8217;ve also performed the test, please share your test results or your thoughts regarding this matter. Thank you!</p><p>Oh yeah, I almost forgot. Make it a habit to download WordPress themes or plugins from reliable sources or directly from the author&#8217;s site. Better safe than sorry!</p><p>Have a good weekend everyone! :)</p><div
id="crp_related"><ul><li><a
href="http://jaypeeonline.net/wordpress/how-to-secure-wordpress/" rel="bookmark" class="crp_title">&#8220;How To Secure WordPress&#8221;</a></li><li><a
href="http://jaypeeonline.net/wordpress/49-most-downloaded-wordpress-themes/" rel="bookmark" class="crp_title">49 Most downloaded WordPress Themes</a></li><li><a
href="http://jaypeeonline.net/wordpress-themes/vistered-little-theme-security-alert/" rel="bookmark" class="crp_title">Vistered Little Theme Security Alert</a></li><li><a
href="http://jaypeeonline.net/wordpress-themes/wp-theme-review-redoable-11/" rel="bookmark" class="crp_title">WP Theme Review: Redoable 1.1</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-2-rc1/" rel="bookmark" class="crp_title">WordPress 3.2 Release Candidate 1</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-4-beta-1-now-available/" rel="bookmark" class="crp_title">WordPress 3.4 Beta 1 Now Available</a></li><li><a
href="http://jaypeeonline.net/wordpress-themes/wp-theme-review-redoable-12/" rel="bookmark" class="crp_title">WP Theme Review: Redoable 1.2</a></li><li><a
href="http://jaypeeonline.net/tips-tricks/wordpress-reverting-default-theme-fix/" rel="bookmark" class="crp_title">WordPress Reverting Default Theme Fix</a></li><li><a
href="http://jaypeeonline.net/wordpress-plugins/wp-plugin-review-theme-authenticity-checker/" rel="bookmark" class="crp_title">WP Plugin Review: TAC (Theme Authenticity Checker)</a></li><li><a
href="http://jaypeeonline.net/wordpress/why-you-shouldnt-look-for-free-wordpress-themes-on-search-engines/" rel="bookmark" class="crp_title">Why You Shouldn&#8217;t Look for Free WordPress Themes on Search Engines</a></li></ul></div>]]></content:encoded> <wfw:commentRss>http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/feed/</wfw:commentRss> <slash:comments>14</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced) (User agent is rejected)
Database Caching 6/10 queries in 0.048 seconds using disk
Object Caching 536/546 objects using disk
Content Delivery Network via maxcdn.jaypeeonline.net

Served from: jaypeeonline.net @ 2012-05-27 04:23:49 -->
