<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>JaypeeOnline &#187; vistered-little</title> <atom:link href="http://jaypeeonline.net/tag/vistered-little/feed/" rel="self" type="application/rss+xml" /><link>http://jaypeeonline.net</link> <description>Technology, Blogging News, WordPress Theme and Plugin Reviews, Tips and Tricks</description> <lastBuildDate>Mon, 21 May 2012 03:17:06 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=</generator> <item><title>Top 10 Vulnerable WP Themes</title><link>http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/</link> <comments>http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/#comments</comments> <pubDate>Fri, 10 Aug 2007 16:23:18 +0000</pubDate> <dc:creator>Jaypee Habaradas</dc:creator> <category><![CDATA[WordPress]]></category> <category><![CDATA[blogsecurity]]></category> <category><![CDATA[cross-site-scripting]]></category> <category><![CDATA[k2]]></category> <category><![CDATA[redoable]]></category> <category><![CDATA[vistered-little]]></category> <category><![CDATA[vulnerable-wordpress-themes]]></category><guid
isPermaLink="false">http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/</guid> <description><![CDATA[BlogSecurity an organization that deals with web blog security recently posted a list of the top 10 WordPress themes that are vulnerable to Cross-Site Scripting due to template flaws. 1. field-of-dreams 2. tarski 3. mandigo-14,1.22 4. connections 5. default 6. freshy 7. redoable 8. k2 9. vistered-little-1.6a 10. wp-multiflex-3 Some of the themes on the [...]]]></description> <content:encoded><![CDATA[<p></p><p><a
href="http://blogsecurity.net/">BlogSecurity</a> an organization that deals with web blog security recently posted a list of the <a
href="http://blogsecurity.net/wordpress/article-050807/">top 10 WordPress themes</a> that are vulnerable to <a
href="http://en.wikipedia.org/wiki/Cross-site_scripting">Cross-Site Scripting</a> due to template flaws.</p><p>1. <a
href="http://www.notsoboringlife.com/the-arts/blogging/wordpress-theme-field-of-dreams/">field-of-dreams</a><br
/> 2. <a
href="http://tarskitheme.com/">tarski</a><br
/> 3. <a
href="http://www.onehertz.com/portfolio/wordpress/mandigo/">mandigo-14,1.22</a><br
/> 4. <a
href="http://vanillamist.com/blog/?page_id=64">connections</a><br
/> 5. default<br
/> 6. <a
href="http://www.jide.fr/english/downloads/template-freshy-wordpress/">freshy</a><br
/> 7. <a
href="http://www.deanjrobinson.com/wordpress/redoable">redoable</a><br
/> 8. <a
href="http://getk2.com/">k2</a><br
/> 9. <a
href="http://windyroad.org/">vistered-little-1.6a</a><br
/> 10. <a
href="http://webgazette.co.uk/web-design/wordpress-themes/wp-multiflex-3/">wp-multiflex-3</a></p><p><span
id="more-368"></span></p><p>Some of the themes on the list are popular WordPress themes, like <strong>freshy</strong>, <strong>k2</strong> and <strong>redoable</strong>. I hope that the theme authors would look into this and make the necessary changes and fix the template flaws.</p><p>If you want to perform the same test for your blog or WordPress themes that you&#8217;ve created, you can use the same method used by BlogSecurity team. All you need to do is follow the installation instructions:</p><ul><li>Download the <a
href="http://blogsecurity.net/projects/wp-scanner.zip">wp-scanner activator</a> plugin.</li><li>Upload the plugin file to your <strong>wp-contents/plugin</strong> folder.</li><li><strong>Activate</strong> the plugin from the admin panel.</li><li><a
href="http://blogsecurity.net/wpscan">Launch the wp-scanner</a> and perform the test.</li><li>As soon as you&#8217;re done, <strong>de-activate</strong> the plugin so other people can&#8217;t to scan your blog.</li></ul><p>Btw, I performed the test for JaypeeOnline and I&#8217;m happy with the result:</p><p><img
src="http://maxcdn.jaypeeonline.net/images/wpscanner_result.jpg" alt="WP Scanner Result for JaypeeOnline" /></p><p>I strongly recommend that you also perform this test so you can find out if the WordPress theme you&#8217;re using is vulnerable or not. It would only take a few minutes of your time. If you&#8217;ve also performed the test, please share your test results or your thoughts regarding this matter. Thank you!</p><p>Oh yeah, I almost forgot. Make it a habit to download WordPress themes or plugins from reliable sources or directly from the author&#8217;s site. Better safe than sorry!</p><p>Have a good weekend everyone! :)</p><div
id="crp_related"><ul><li><a
href="http://jaypeeonline.net/wordpress/how-to-secure-wordpress/" rel="bookmark" class="crp_title">&#8220;How To Secure WordPress&#8221;</a></li><li><a
href="http://jaypeeonline.net/wordpress/49-most-downloaded-wordpress-themes/" rel="bookmark" class="crp_title">49 Most downloaded WordPress Themes</a></li><li><a
href="http://jaypeeonline.net/wordpress-themes/vistered-little-theme-security-alert/" rel="bookmark" class="crp_title">Vistered Little Theme Security Alert</a></li><li><a
href="http://jaypeeonline.net/wordpress-themes/wp-theme-review-redoable-11/" rel="bookmark" class="crp_title">WP Theme Review: Redoable 1.1</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-2-rc1/" rel="bookmark" class="crp_title">WordPress 3.2 Release Candidate 1</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-4-beta-1-now-available/" rel="bookmark" class="crp_title">WordPress 3.4 Beta 1 Now Available</a></li><li><a
href="http://jaypeeonline.net/wordpress-themes/wp-theme-review-redoable-12/" rel="bookmark" class="crp_title">WP Theme Review: Redoable 1.2</a></li><li><a
href="http://jaypeeonline.net/tips-tricks/wordpress-reverting-default-theme-fix/" rel="bookmark" class="crp_title">WordPress Reverting Default Theme Fix</a></li><li><a
href="http://jaypeeonline.net/wordpress-plugins/wp-plugin-review-theme-authenticity-checker/" rel="bookmark" class="crp_title">WP Plugin Review: TAC (Theme Authenticity Checker)</a></li><li><a
href="http://jaypeeonline.net/wordpress/why-you-shouldnt-look-for-free-wordpress-themes-on-search-engines/" rel="bookmark" class="crp_title">Why You Shouldn&#8217;t Look for Free WordPress Themes on Search Engines</a></li></ul></div>]]></content:encoded> <wfw:commentRss>http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/feed/</wfw:commentRss> <slash:comments>14</slash:comments> </item> <item><title>Vistered Little Theme Security Alert</title><link>http://jaypeeonline.net/wordpress-themes/vistered-little-theme-security-alert/</link> <comments>http://jaypeeonline.net/wordpress-themes/vistered-little-theme-security-alert/#comments</comments> <pubDate>Wed, 30 May 2007 03:41:30 +0000</pubDate> <dc:creator>Jaypee Habaradas</dc:creator> <category><![CDATA[WordPress Themes]]></category> <category><![CDATA[2-column]]></category> <category><![CDATA[fixed-width]]></category> <category><![CDATA[theme]]></category> <category><![CDATA[vistered-little]]></category> <category><![CDATA[widget-ready]]></category><guid
isPermaLink="false">http://jaypeeonline.net/?p=282</guid> <description><![CDATA[Anyone who&#8217;s using the Vistered Little Theme other than the latest version 1.7.3, are strongly advised to immediately upgrade due to a vulnerability that has been recently discovered. From the author&#8217;s blog: Wordpress Blogs using Vistered Little are being targeted by hackers. Over the last two days the number of 404s on my site increased [...]]]></description> <content:encoded><![CDATA[<p></p><p>Anyone who&#8217;s using the Vistered Little Theme other than the latest version 1.7.3, are strongly advised to immediately upgrade due to a <a
href="http://windyroad.org/2007/05/30/security-alert-for-vistered-little-theme/">vulnerability</a> that has been recently discovered.</p><p>From the author&#8217;s blog:</p><blockquote><p> Wordpress Blogs using Vistered Little are being targeted by hackers. Over the last two days the number of 404s on my site increased significantly. Further investigation revealed that attempts were being made to access the following URLs to gain access to files they wouldn&#8217;t normally have access to.</p><p>It appears the skins/common.css.php is vulnerable. This file existing in that location in 1.6a and within the theme&#8217;s root directory in 1.7.0 through to 1.7.2. This file does not exist in the current version 1.7.3.</p></blockquote><p>For those who can&#8217;t do the upgrade, another option would be to switch to another theme and immediately delete the Vistered Little theme folder from your <strong>wp-content/themes</strong> folder.</p><p>A little background:</p><p><strong>Screenshot:</strong></p><p><img
src="http://maxcdn.jaypeeonline.net/images/vistered_little.jpg" alt="WP Theme Vistered Little" /></p><p>Vistered Little is a 2 column, fixed width, widget-ready theme from <a
href="http://windyroad.org/">Windy Road</a> and is one of the most popular and most downloaded <a
href="http://jaypeeonline.net/category/wordpress-themes/">WordPress themes</a>. Vistered Little has a highly customisable glass-like interface with wallpaper and skin support. This theme makes use of the <a
href="http://windyroad.org/software/wordpress/skinner-plugin">Skinner</a> and <a
href="http://windyroad.org/software/wordpress/presentation-toolkit-plugin">Presentation Toolkit</a> plugins.</p><p>Upgrade to <a
href="http://windyroad.org/software/wordpress/vistered-little-theme/">Vistered Little 1.7.3</a> now!</p><div
id="crp_related"><ul><li><a
href="http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/" rel="bookmark" class="crp_title">Top 10 Vulnerable WP Themes</a></li><li><a
href="http://jaypeeonline.net/wordpress-plugins/deans-fckeditor-with-pwwangs-code-for-wordpress-security-vulnerability/" rel="bookmark" class="crp_title">Deans FCKEditor with PWWANGS Code for WordPress(version 1.0.0) Security Vulnerability</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-211-dangerous-download/" rel="bookmark" class="crp_title">WordPress 2.1.1 &#8211; Dangerous Download</a></li><li><a
href="http://jaypeeonline.net/tips-tricks/timthumb-zero-day-vulnerability/" rel="bookmark" class="crp_title">WARNING: Zero Day Vulnerability Found on Timthumb.php</a></li><li><a
href="http://jaypeeonline.net/tips-tricks/wordpress-reverting-default-theme-fix/" rel="bookmark" class="crp_title">WordPress Reverting Default Theme Fix</a></li><li><a
href="http://jaypeeonline.net/wordpress/upgraded-to-wordpress-221/" rel="bookmark" class="crp_title">Upgraded To WordPress 2.2.1</a></li><li><a
href="http://jaypeeonline.net/wordpress-themes/wp-theme-review-sakura/" rel="bookmark" class="crp_title">WP Theme Review: Sakura</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-223-security-release/" rel="bookmark" class="crp_title">WordPress 2.2.3 Security Release</a></li><li><a
href="http://jaypeeonline.net/wordpress-plugins/wp-plugin-review-theme-authenticity-checker/" rel="bookmark" class="crp_title">WP Plugin Review: TAC (Theme Authenticity Checker)</a></li><li><a
href="http://jaypeeonline.net/wordpress-themes/swfpress/" rel="bookmark" class="crp_title">Create Flash-Based WordPress Themes w/ SWFPress</a></li></ul></div>]]></content:encoded> <wfw:commentRss>http://jaypeeonline.net/wordpress-themes/vistered-little-theme-security-alert/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced) (User agent is rejected)
Database Caching 5/11 queries in 0.090 seconds using disk
Object Caching 770/780 objects using disk
Content Delivery Network via maxcdn.jaypeeonline.net

Served from: jaypeeonline.net @ 2012-05-27 10:57:39 -->
