<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WPsecure&#187; Exploits</title>
	<atom:link href="http://wpsecure.net/category/exploits/feed/" rel="self" type="application/rss+xml" />
	<link>http://wpsecure.net</link>
	<description>Securing your Wordpress</description>
	<lastBuildDate>Wed, 01 May 2013 18:15:27 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Open flash chart</title>
		<link>http://wpsecure.net/2013/05/open-flash-chart/</link>
		<comments>http://wpsecure.net/2013/05/open-flash-chart/#comments</comments>
		<pubDate>Wed, 01 May 2013 18:15:27 +0000</pubDate>
		<dc:creator>wpsecure</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wpsecure.net/?p=61856</guid>
		<description><![CDATA[A vulnerability has been discovered in Open flash chart  plugin which can be exploited to compromise a vulnerable system.]]></description>
				<content:encoded><![CDATA[A vulnerability has been discovered in Open flash chart  plugin which can be exploited to compromise a vulnerable system.]]></content:encoded>
			<wfw:commentRss>http://wpsecure.net/2013/05/open-flash-chart/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A list of recent XSS plugin exploits from April.</title>
		<link>http://wpsecure.net/2013/05/a-list-of-recent-xss-plugin-exploits-from-april/</link>
		<comments>http://wpsecure.net/2013/05/a-list-of-recent-xss-plugin-exploits-from-april/#comments</comments>
		<pubDate>Wed, 01 May 2013 18:07:37 +0000</pubDate>
		<dc:creator>wpsecure</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[exploit]]></category>

		<guid isPermaLink="false">http://wpsecure.net/?p=61853</guid>
		<description><![CDATA[XSS vulnerabilities for April.]]></description>
				<content:encoded><![CDATA[<ul>
<li>WordPress Facebook Members &#8211; <em>5.0.4</em> &#8211; <a href="https://secunia.com/advisories/52962/">XSS</a></li>
<li>WordPress FourSquare Checkins Plugin &#8211; <em>1.2</em> &#8211; <a href="https://secunia.com/advisories/53151/">XSS</a></li>
<li>WordPress Formidable Pro &#8211; <em>1.06.08 </em>- <a href="https://secunia.com/advisories/53121/">XSS</a></li>
<li> All in One Webmaster plugin &#8211; <em>8.2.3</em> &#8211; <a href="https://secunia.com/advisories/52877/">XSS</a></li>
<li>WordPress Background Music Plugin &#8220;jPlayer&#8221; &#8211; <em>1.0</em> &#8211; <a href="https://secunia.com/advisories/53057/">XSS</a></li>
<li>Haiku minimalist audio player &#8211; <em>1.0 </em>- <a href="https://secunia.com/advisories/51336/">XSS</a></li>
<li>Jammer plugin &#8211; <em>0.2 </em>- <a href="https://secunia.com/advisories/53106/">XSS</a> </li>
<li>SyntaxHighlighter Evolved &#8211; <em>3.1.6</em> &#8211; <a href="https://secunia.com/advisories/53235/">XSS</a></li>
<li>Top 10 plugin &#8211; <em>1.9.2</em> &#8211; <a href="https://secunia.com/advisories/53205/">XSS</a></li>
<li>Easy AdSense Lite &#8211; <em>6.06</em> &#8211; <a href="https://secunia.com/advisories/52953/">XSS</a></li>
<li>WordPress Social Media Widget Plugin &#8211; versions 3.1, 3.2, and 3.3 before 2013-04-11 and in version 4.0.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://wpsecure.net/2013/05/a-list-of-recent-xss-plugin-exploits-from-april/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress SEO by Yoast</title>
		<link>http://wpsecure.net/2013/04/wordpress-seo-by-yoast/</link>
		<comments>http://wpsecure.net/2013/04/wordpress-seo-by-yoast/#comments</comments>
		<pubDate>Wed, 10 Apr 2013 18:29:28 +0000</pubDate>
		<dc:creator>wpsecure</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wpsecure.net/?p=61752</guid>
		<description><![CDATA[A vulnerability has been discovered in WordPress SEO by Yoast which can be exploited to compromise a vulnerable system.]]></description>
				<content:encoded><![CDATA[A vulnerability has been discovered in WordPress SEO by Yoast which can be exploited to compromise a vulnerable system.]]></content:encoded>
			<wfw:commentRss>http://wpsecure.net/2013/04/wordpress-seo-by-yoast/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WP125 Ad squares plugin</title>
		<link>http://wpsecure.net/2013/04/wp125-ad-squares-plugin/</link>
		<comments>http://wpsecure.net/2013/04/wp125-ad-squares-plugin/#comments</comments>
		<pubDate>Wed, 10 Apr 2013 18:25:38 +0000</pubDate>
		<dc:creator>wpsecure</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wpsecure.net/?p=61750</guid>
		<description><![CDATA[A vulnerability has been discovered in the WP125 plugin which can be exploited to compromise a vulnerable system.]]></description>
				<content:encoded><![CDATA[A vulnerability has been discovered in the WP125 plugin which can be exploited to compromise a vulnerable system.]]></content:encoded>
			<wfw:commentRss>http://wpsecure.net/2013/04/wp125-ad-squares-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WP-DownloadManager</title>
		<link>http://wpsecure.net/2013/04/wp-downloadmanager/</link>
		<comments>http://wpsecure.net/2013/04/wp-downloadmanager/#comments</comments>
		<pubDate>Wed, 10 Apr 2013 18:23:10 +0000</pubDate>
		<dc:creator>wpsecure</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wpsecure.net/?p=61748</guid>
		<description><![CDATA[A vulnerability has been discovered in the WP-DownloadManager plugin which can be exploited to compromise a vulnerable system.]]></description>
				<content:encoded><![CDATA[A vulnerability has been discovered in the WP-DownloadManager plugin which can be exploited to compromise a vulnerable system.]]></content:encoded>
			<wfw:commentRss>http://wpsecure.net/2013/04/wp-downloadmanager/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WP-Print plugin</title>
		<link>http://wpsecure.net/2013/04/wp-print-plugin/</link>
		<comments>http://wpsecure.net/2013/04/wp-print-plugin/#comments</comments>
		<pubDate>Wed, 10 Apr 2013 18:18:43 +0000</pubDate>
		<dc:creator>wpsecure</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wpsecure.net/?p=61746</guid>
		<description><![CDATA[A vulnerability has been discovered in the WP-Print plugin which can be exploited to compromise a vulnerable system.]]></description>
				<content:encoded><![CDATA[A vulnerability has been discovered in the WP-Print plugin which can be exploited to compromise a vulnerable system.]]></content:encoded>
			<wfw:commentRss>http://wpsecure.net/2013/04/wp-print-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Several XSS in the following plugins.</title>
		<link>http://wpsecure.net/2013/04/several-xss-in-the-following-plugins/</link>
		<comments>http://wpsecure.net/2013/04/several-xss-in-the-following-plugins/#comments</comments>
		<pubDate>Mon, 01 Apr 2013 17:44:18 +0000</pubDate>
		<dc:creator>wpsecure</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wpsecure.net/?p=61670</guid>
		<description><![CDATA[Several XSS in the following plugins: Occasions, FAQs Manager plugin,  Simply Poll plugin for WordPress.]]></description>
				<content:encoded><![CDATA[<p><strong>Occasion:</strong></p>
<p>The application allows users to perform certain actions via HTTP requests without performing proper validity checks to verify the requests. This can be exploited to e.g. add or delete occasions when a logged-in user visits a specially crafted web page.</p>
<p>The vulnerability is confirmed in version 1.0.4. Other versions may also be affected.</p>
<p>&nbsp;</p>
<p><strong>Simply Poll</strong></p>
<p>The application allows users to perform certain actions via HTTP requests without performing proper validity checks to verify the requests. This can be exploited to e.g. remove or edit a poll when a logged-in user visits a specially crafted web page.</p>
<p>The vulnerability is reported in version 1.4.1. Other versions may also be affected.</p>
<p>&nbsp;</p>
<p><strong>FAQs Manager plugin</strong></p>
<p>1) The application allows users to perform certain actions via HTTP requests without performing proper validity checks to verify the requests. This can be exploited to e.g. change plugin settings when a logged-in user visits a specially crafted web page.</p>
<p>2) Input passed via the &#8220;question&#8221; POST parameter to wp-admin/admin-ajax.php (when &#8220;action&#8221; is set to &#8220;inic_faq_questions&#8221;) is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user&#8217;s browser session in context of an affected site if malicious data is viewed.</p>
<p>The vulnerabilities are confirmed in version 1.0. Other versions may also be affected.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://wpsecure.net/2013/04/several-xss-in-the-following-plugins/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>JC Coupon</title>
		<link>http://wpsecure.net/2013/03/jc-coupon/</link>
		<comments>http://wpsecure.net/2013/03/jc-coupon/#comments</comments>
		<pubDate>Thu, 14 Mar 2013 20:48:12 +0000</pubDate>
		<dc:creator>wpsecure</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wpsecure.net/?p=61653</guid>
		<description><![CDATA[A vulnerability has been discovered in the JC Coupon plugin which can be exploited to compromise a vulnerable system.]]></description>
				<content:encoded><![CDATA[A vulnerability has been discovered in the JC Coupon plugin which can be exploited to compromise a vulnerable system.]]></content:encoded>
			<wfw:commentRss>http://wpsecure.net/2013/03/jc-coupon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tiny URL plugin</title>
		<link>http://wpsecure.net/2013/03/tiny-url-plugin/</link>
		<comments>http://wpsecure.net/2013/03/tiny-url-plugin/#comments</comments>
		<pubDate>Thu, 14 Mar 2013 20:45:24 +0000</pubDate>
		<dc:creator>wpsecure</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wpsecure.net/?p=61651</guid>
		<description><![CDATA[A vulnerability has been discovered in the Tiny URL plugin which can be exploited to compromise a vulnerable system]]></description>
				<content:encoded><![CDATA[A vulnerability has been discovered in the Tiny URL plugin which can be exploited to compromise a vulnerable system]]></content:encoded>
			<wfw:commentRss>http://wpsecure.net/2013/03/tiny-url-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cleeng Content Monetization</title>
		<link>http://wpsecure.net/2013/03/cleeng-content-monetization/</link>
		<comments>http://wpsecure.net/2013/03/cleeng-content-monetization/#comments</comments>
		<pubDate>Thu, 14 Mar 2013 20:43:09 +0000</pubDate>
		<dc:creator>wpsecure</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wpsecure.net/?p=61649</guid>
		<description><![CDATA[A vulnerability has been discovered in the Cleeng Content Monetization plugin which can be exploited to compromise a vulnerable system]]></description>
				<content:encoded><![CDATA[A vulnerability has been discovered in the Cleeng Content Monetization plugin which can be exploited to compromise a vulnerable system]]></content:encoded>
			<wfw:commentRss>http://wpsecure.net/2013/03/cleeng-content-monetization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced
Database Caching 5/13 queries in 0.014 seconds using disk: basic
Object Caching 660/671 objects using disk: basic

 Served from: wpsecure.net @ 2013-05-20 06:23:53 by W3 Total Cache -->