Top 10 Vulnerable WP Themes

Top 10 Vulnerable WP Themes

10 Aug 2007 ·

WordPress


BlogSecurity an organization that deals with web blog security recently posted a list of the top 10 WordPress themes that are vulnerable to Cross-Site Scripting due to template flaws.

1. field-of-dreams
2. tarski
3. mandigo-14,1.22
4. connections
5. default
6. freshy
7. redoable
8. k2
9. vistered-little-1.6a
10. wp-multiflex-3

Some of the themes on the list are popular WordPress themes, like freshy, k2 and redoable. I hope that the theme authors would look into this and make the necessary changes and fix the template flaws.

If you want to perform the same test for your blog or WordPress themes that you’ve created, you can use the same method used by BlogSecurity team. All you need to do is follow the installation instructions:

  • Download the wp-scanner activator plugin.
  • Upload the plugin file to your wp-contents/plugin folder.
  • Activate the plugin from the admin panel.
  • Launch the wp-scanner and perform the test.
  • As soon as you’re done, de-activate the plugin so other people can’t to scan your blog.

Btw, I performed the test for JaypeeOnline and I’m happy with the result:

WP Scanner Result for JaypeeOnline

I strongly recommend that you also perform this test so you can find out if the WordPress theme you’re using is vulnerable or not. It would only take a few minutes of your time. If you’ve also performed the test, please share your test results or your thoughts regarding this matter. Thank you!

Oh yeah, I almost forgot. Make it a habit to download WordPress themes or plugins from reliable sources or directly from the author’s site. Better safe than sorry!

Have a good weekend everyone! :)


Subscribe to JaypeeOnline's RSS feed  Share this on del.icio.us  Stumble It!  Digg this!  Share this on Facebook  Tweet this!  Share on FriendFeed  Bookmark It!  Submit to Reddit!  Email this story to a friend!
Written by Jaypee Habaradas
Owner and editor of JaypeeOnline. Self-proclaimed geek. New media writer and consultant. WordPress advocate. Loves blogging, gadgets, video games and sports. You can follow him on Twitter @jaypee or Facebook.
Don't miss a single post and receive FREE updates on your email inbox. Subscribe NOW!

Enter your email address:

*Don't forget to verify your subscription by clicking the link on the email that Feedburner will send you.*

Didn't find what you're looking for? Try looking for it again.

Related Posts

Related Ads

























, , , , ,

**Comments posted on JaypeeOnline are moderated. I reserve the right to edit/delete comments that contain words or phrases that are defamatory, abusive, incite hatred and advertise an email address, commercial services or spammy.


14 Responses to “Top 10 Vulnerable WP Themes”

  1. Jaypee UNITED STATES Mozilla Firefox Ubuntu Linux Says:

    @jhay – That’s good. This is cool because now we can use this plugin to test a theme before using it on our blog, right? Thanks! :)

    Reply

  2. jhay PHILIPPINES Mozilla Firefox Windows Says:

    Whew, it’s a good thing my theme checked out fine.

    Quite a nifty plugin you found dude.

    Reply

  3. Jaypee UNITED STATES Mozilla Firefox Ubuntu Linux Says:

    @iskoo – Thanks! Let me know what you got in your results, ok? :)

    Reply

  4. iskoo PHILIPPINES Mozilla Firefox Windows Says:

    good info, i check mine..

    Reply

  5. Jaypee UNITED STATES Mozilla Firefox Ubuntu Linux Says:

    @benj – What happened? Do you have a screenshot? Let me know if you’re still experiencing the problem and I’ll try to help you out.

    Reply

  6. benj PHILIPPINES Mozilla Firefox Windows Says:

    Ok, my site just got messed up with Firefox. I wasn’t doing anything! It still works fine with IE and Opera though. Halp! :cry:

    Reply

  7. Jaypee UNITED STATES Mozilla Firefox Ubuntu Linux Says:

    @Manila Freelancer – You’re welcome! Care to share your test results? :)

    Reply

  8. Manila Freelancer PHILIPPINES Internet Explorer Windows Says:

    Ill check my themes vulnerability later on… thanks for the tip

    Reply

  9. Jaypee UNITED STATES Mozilla Firefox Windows Says:

    @K – It doesn’t matter where themes are hosted coz it’s involves the template codes and stuff. As long as you use one of the those themes listed and as long as the authors don’t fix it, they’d remain vulnerable.

    Reply

  10. K HONG KONG Safari Mac OS Says:

    Does this affect themes from wp.com? I’m glad my current (Unsleepable) is not on this list.

    Reply

Don't Be Shy. Share your thoughts!

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Trackbacks/Pingbacks

  1. [...] So what to do when there are no classes and you can’t go anywhere because mother nature is bitching outdoors? Well, as you can see from what I’ve done you can sit for 9 hours in front of your computer and prowl YouTube for sex scandal videos, make money off the internets, and completely forget about taking a bath change the theme of your blog (Honestly, that’s all what I did). Coincidentally, Shari who’s got an award named after her (awesome!) chose to do the same thing and use the same theme. Notice how I tweaked the headings of my sidebar in order to make it more “human” and less Google-bot slave? It’s a good thing this theme is not among the vulnerable ones. [...]

  2. [...] Top 10 Vulnerable WP Themes : JaypeeOnline | Blogging News & Reviews [...]

  3. [...] Top 10 Vulnerable WP Themes : JaypeeOnline | Blogging News & Reviews [...]

You May Also Like -

Why You Shouldn't Look for Free WordPress Themes on Search EnginesWhy You Shouldn't Look for Free WordPress Themes on Search EnginesOne of the common trends in the Internet is that anytime something becomes big ...