WordCamp Philippines

WordCamp Philippines

If you’re a Pinoy blogger or a WordPress user/fan then most likely you’ve heard or read of this already. But in case you haven’t, I have good news for you. There will be a WordCamp held in the Philippines this coming September 6, 2008. If you don’t know what I’m talking about here’s a little info.

What is WordCamp?

WordCamp is a conference type of event that focuses squarely on everything WordPress. Everyone from casual end users all the way up to core developers show up to these events. These events are usually highlighted by speeches or keynotes by various people. WordCamp is a spin off from the popular BarCamp which was a spin off of FooCamp. - Weblog Tools Collection

WordCamp Philippines will be the first ever WordCamp organized and held in Asia. WordCamp Philippines is being organized by a group of Filipino bloggers based in Mindanao who were also responsible for organizing the successful 1st Mindanao Bloggers Summit held last year.

What are the objectives of WordCamp Philippines?

…to encourage more developers to use and deploy WordPress, not only as a blogging engine but also as a full-featured content management system for Web sites. Another is to increase the number of WordPress users and developers in the country. By developers, we mean programmers of WordPress plugins and designers of themes & templates.



Top 10 Vulnerable WP Themes
14 Comments 2748 Views

« Modern Skate & Surf What’s In The Box? »



BlogSecurity an organization that deals with web blog security recently posted a list of the top 10 WordPress themes that are vulnerable to Cross-Site Scripting due to template flaws.

1. field-of-dreams
2. tarski
3. mandigo-14,1.22
4. connections
5. default
6. freshy
7. redoable
8. k2
9. vistered-little-1.6a
10. wp-multiflex-3

Some of the themes on the list are popular WordPress themes, like freshy, k2 and redoable. I hope that the theme authors would look into this and make the necessary changes and fix the template flaws.

If you want to perform the same test for your blog or WordPress themes that you’ve created, you can use the same method used by BlogSecurity team. All you need to do is follow the installation instructions:

  • Download the wp-scanner activator plugin.
  • Upload the plugin file to your wp-contents/plugin folder.
  • Activate the plugin from the admin panel.
  • Launch the wp-scanner and perform the test.
  • As soon as you’re done, de-activate the plugin so other people can’t to scan your blog.

Btw, I performed the test for JaypeeOnline and I’m happy with the result:

WP Scanner Result for JaypeeOnline

I strongly recommend that you also perform this test so you can find out if the WordPress theme you’re using is vulnerable or not. It would only take a few minutes of your time. If you’ve also performed the test, please share your test results or your thoughts regarding this matter. Thank you!

Oh yeah, I almost forgot. Make it a habit to download WordPress themes or plugins from reliable sources or directly from the author’s site. Better safe than sorry!

Have a good weekend everyone! :)

(7 votes, average: 5 out of 5)
If you enjoyed the article, why not subscribe?

Related Ads

Related Posts



14 Responses to “Top 10 Vulnerable WP Themes”

  1. MyAvatars 0.2   K HONG KONG Mac OS X Safari 419.3 on Aug 10, 2007 | 3:46 pm | Reply

    Does this affect themes from wp.com? I’m glad my current (Unsleepable) is not on this list.

  2. MyAvatars 0.2   Jaypee UNITED STATES Windows XP Mozilla Firefox 2.0.0.6 on Aug 10, 2007 | 8:40 pm | Reply

    @K - It doesn’t matter where themes are hosted coz it’s involves the template codes and stuff. As long as you use one of the those themes listed and as long as the authors don’t fix it, they’d remain vulnerable.


  3. Ill check my themes vulnerability later on… thanks for the tip

  4. MyAvatars 0.2   Jaypee UNITED STATES Ubuntu Linux Mozilla Firefox 2.0.0.4 on Aug 11, 2007 | 5:30 am | Reply

    @Manila Freelancer - You’re welcome! Care to share your test results? :)

  5. MyAvatars 0.2   benj PHILIPPINES Windows Vista Mozilla Firefox 2.0.0.4 on Aug 11, 2007 | 7:43 am | Reply

    Ok, my site just got messed up with Firefox. I wasn’t doing anything! It still works fine with IE and Opera though. Halp! :cry:

  6. MyAvatars 0.2   Jaypee UNITED STATES Ubuntu Linux Mozilla Firefox 2.0.0.4 on Aug 11, 2007 | 8:00 am | Reply

    @benj - What happened? Do you have a screenshot? Let me know if you’re still experiencing the problem and I’ll try to help you out.

  7. MyAvatars 0.2   iskoo PHILIPPINES Windows XP Mozilla Firefox 2.0.0.6 on Aug 11, 2007 | 10:06 pm | Reply

    good info, i check mine..

  8. MyAvatars 0.2   Jaypee UNITED STATES Ubuntu Linux Mozilla Firefox 2.0.0.4 on Aug 11, 2007 | 10:30 pm | Reply

    @iskoo - Thanks! Let me know what you got in your results, ok? :)

  9. MyAvatars 0.2   jhay PHILIPPINES Windows XP Mozilla Firefox 2.0.0.6 on Aug 12, 2007 | 5:13 am | Reply

    Whew, it’s a good thing my theme checked out fine.

    Quite a nifty plugin you found dude.

  10. MyAvatars 0.2   Jaypee UNITED STATES Ubuntu Linux Mozilla Firefox 2.0.0.4 on Aug 12, 2007 | 6:51 am | Reply

    @jhay - That’s good. This is cool because now we can use this plugin to test a theme before using it on our blog, right? Thanks! :)

Sign up for PayPal and start accepting credit card payments instantly.

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

« Modern Skate & Surf What’s In The Box? »


 Subscribe in a reader Or, subscribe via email:
Enter your email address: 
 
Feedburner
Google