<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; wordpress security</title>
	<atom:link href="http://www.ghacks.net/tag/wordpress-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Mon, 23 Nov 2009 22:22:46 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Wordpress 2.8.6 Security Update</title>
		<link>http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/</link>
		<comments>http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 23:40:02 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[The Web]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress 2.8.6]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=18457</guid>
		<description><![CDATA[The Wordpress developers have just released a security update for their blogging platform Wordpress which raises the version of the software to 2.8.6. It is always recommended to update to a new version of Wordpress as soon as possible and especially so for a security release. This release fixes two vulnerabilities that are only relevant [...]]]></description>
			<content:encoded><![CDATA[<p>The Wordpress developers have just released a security update for their blogging platform Wordpress which raises the version of the software to 2.8.6. It is always recommended to update to a new version of Wordpress as soon as possible and especially so for a security release. This release fixes two vulnerabilities that are only relevant for multi-author blogs as they can only be exploited by registered, logged in users with posting rights. This security vulnerability is therefor not affecting the majority of Wordpress blogs but those webmasters should nevertheless consider upgrading their blog software right away.</p>
<p><span id="more-18457"></span><br />
<blockquote>The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch.  The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.</p></blockquote>
<p>The upgrade is as usual available through various means with the two most popular ones being through an automatic update in the Wordpress admin interface and the second trough a download from the <a href="http://wordpress.org/download/">official</a> Wordpress website. The first is faster and more comfortable while the second offers more control to the user especially if something goes wrong.</p>
<p>This Wordpress update does not require an update of the Wordpress database. It is however recommended to perform a backup of both the Wordpress files on the web server and the MySQL database to be prepared if the update should fail for any reason.</p>

	Tags: <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-2-8-6/" title="wordpress 2.8.6" rel="tag">wordpress 2.8.6</a>, <a href="http://www.ghacks.net/tag/wordpress-security/" title="wordpress security" rel="tag">wordpress security</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/" title="Wordpress 2.8.5 Security Update (October 21, 2009)">Wordpress 2.8.5 Security Update</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/15/wordpress-261-released/" title="Wordpress 2.6.1 released (August 15, 2008)">Wordpress 2.6.1 released</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/08/04/wordpress-2-8-3/" title="Wordpress 2.8.3 (August 4, 2009)">Wordpress 2.8.3</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.8.5 Security Update</title>
		<link>http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/</link>
		<comments>http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 13:53:23 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[The Web]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wordpress update]]></category>
		<category><![CDATA[wordpress upgrade]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=17549</guid>
		<description><![CDATA[The Wordpress developers have released version 2.8.5 of their popular blogging software. The version is considered a security upgrade and therefor mandatory for all Wordpress blog owners who run their own Wordpress blog (but not those running a blog at Wordpress.com). The developers are calling this released a hardening release as it tightens Wordpress security [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/08/wordpress.gif" alt="wordpress" title="wordpress" width="166" height="142" class="alignleft size-full wp-image-15748" />The Wordpress developers have released version 2.8.5 of their popular blogging software. The version is considered a security upgrade and therefor mandatory for all Wordpress blog owners who run their own Wordpress blog (but not those running a blog at Wordpress.com). The developers are calling this released a hardening release as it tightens Wordpress security to make Wordpress blogs more secure than before. The release is also fixing a Trackback denial of service attack that is currently in the wild.</p>
<p>The most important changes in Wordpress 2.8.5 are therefor:</p>
<ul>
<li>A fix for the Trackback Denial-of-Service attack that is currently being seen.</li>
<li>Removal of areas within the code where php code in variables was evaluated.</li>
<li>Switched the file upload functionality to be whitelisted for all users including Admins.</li>
<li>Retiring of the two importers of Tag data from old plugins.</li>
</ul>
<p><span id="more-17549"></span>Wordpress blogs are currently not announcing the new release. It is expected that this will change in the next hours so that the automatic update option becomes available for Wordpress webmasters who use it to update their website. Webmasters who manually update their blog can <a href="http://wordpress.org/">visit</a> the Wordpress page to download the latest version of Wordpress. Additional information about the security release are available in the blog <a href="http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/">post</a> that announced the upgrade.</p>

	Tags: <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-security/" title="wordpress security" rel="tag">wordpress security</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a>, <a href="http://www.ghacks.net/tag/wordpress-upgrade/" title="wordpress upgrade" rel="tag">wordpress upgrade</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/" title="Wordpress 2.8.6 Security Update (November 13, 2009)">Wordpress 2.8.6 Security Update</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/15/wordpress-261-released/" title="Wordpress 2.6.1 released (August 15, 2008)">Wordpress 2.6.1 released</a> (1)</li>
	<li><a href="http://www.ghacks.net/2007/09/25/dont-upgrade-to-wordpress-23-yet/" title="Don&#8217;t upgrade to Wordpress 2.3 yet (September 25, 2007)">Don&#8217;t upgrade to Wordpress 2.3 yet</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.8.2 Security Patch</title>
		<link>http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/</link>
		<comments>http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 10:00:25 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blogging platform]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress 2.8.2]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=14549</guid>
		<description><![CDATA[A new version of the popular blogging platform Wordpress was released just a few minutes ago. It is an unexpected upgrade considering that the last Wordpress update was less than two weeks ago. The new update fixes a security vulnerability that affects all but the latest version of Wordpress.
The XSS vulnerability could be used to [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/wordpress.png" alt="wordpress" title="wordpress" width="128" height="128" class="alignleft size-full wp-image-11834" />A new version of the popular blogging platform Wordpress was released just a few minutes ago. It is an unexpected upgrade considering that the last Wordpress update was less than two weeks ago. The new update fixes a security vulnerability that affects all but the latest version of Wordpress.</p>
<p><a href="http://wordpress.org/development/2009/07/wordpress-2-8-2/">The</a> XSS vulnerability could be used to create comment author urls that would redirect the system administrator away from the blog&#8217;s website to another site to exploit the situation. Wordpress webmasters are encouraged to update their blogs as soon as possible to patch the security vulnerability.</p>
<p><span id="more-14549"></span>Updates are available directly from within the Wordpress interface if the correct server login information are supplied or by updating the traditional way which would mean to <a href="http://wordpress.org/download/">download</a> the Wordpress release from the Wordpress website, upload it to the web server and run the upgrade command manually. The release information should also be displayed prominently in the Wordpress admin interface with a link to the automatic update script of Wordpress.</p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/blogging-platform/" title="blogging platform" rel="tag">blogging platform</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-2-8-2/" title="wordpress 2.8.2" rel="tag">wordpress 2.8.2</a>, <a href="http://www.ghacks.net/tag/wordpress-security/" title="wordpress security" rel="tag">wordpress security</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/06/11/wordpress-2-8/" title="Wordpress 2.8 (June 11, 2009)">Wordpress 2.8</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/15/wordpress-261-released/" title="Wordpress 2.6.1 released (August 15, 2008)">Wordpress 2.6.1 released</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/" title="Wordpress 2.8.6 Security Update (November 13, 2009)">Wordpress 2.8.6 Security Update</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/" title="Wordpress 2.8.5 Security Update (October 21, 2009)">Wordpress 2.8.5 Security Update</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.6.5 Security Update</title>
		<link>http://www.ghacks.net/2008/11/25/wordpress-265-security-update/</link>
		<comments>http://www.ghacks.net/2008/11/25/wordpress-265-security-update/#comments</comments>
		<pubDate>Tue, 25 Nov 2008 21:23:19 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blog software]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[Wordpress 2.6.5]]></category>
		<category><![CDATA[wordpress blog]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=8541</guid>
		<description><![CDATA[The Wordpress development team has released version 2.6.5 of the blogging plattform for download. The release fixes one security update and three bugs and can be downloaded from the official Wordpress website.
Alternatively only the files wp-includes/feed.php and wp-includes/version.php can be copied from the new release over the old files to update the blog. The security [...]]]></description>
			<content:encoded><![CDATA[<p>The Wordpress development team has released version 2.6.5 of the blogging plattform for download. The release fixes one security update and three bugs and can be <a href="http://wordpress.org/download/">downloaded</a> from the official Wordpress website.</p>
<p>Alternatively only the files wp-includes/feed.php and wp-includes/version.php can be copied from the new release over the old files to update the blog. The security vulnerability is unlikely to affect a large number of Wordpress blogs though as it only only affects IP-based virtual servers running on Apache 2.x.</p>
<p>There might also be some confusion about the versioning of Wordpress. The last official Wordpress version was Wordpress 2.6.3. Wordpress 2.6.4 was skipped because of a fake malicious release that made its round. The official new release is therefor Wordpress 2.6.5.</p>
<p><span id="more-8541"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/blog-software/" title="blog software" rel="tag">blog software</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-265/" title="Wordpress 2.6.5" rel="tag">Wordpress 2.6.5</a>, <a href="http://www.ghacks.net/tag/wordpress-blog/" title="wordpress blog" rel="tag">wordpress blog</a>, <a href="http://www.ghacks.net/tag/wordpress-security/" title="wordpress security" rel="tag">wordpress security</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/02/11/wordpress-271-update/" title="Wordpress 2.7.1 Update (February 11, 2009)">Wordpress 2.7.1 Update</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/08/15/wordpress-261-released/" title="Wordpress 2.6.1 released (August 15, 2008)">Wordpress 2.6.1 released</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/04/25/wordpress-251-released/" title="Wordpress 2.5.1 released (April 25, 2008)">Wordpress 2.5.1 released</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/02/02/wordpress-your-attempt-to-edit-this-post-has-failed/" title="Wordpress: Your attempt to edit this post has failed (February 2, 2009)">Wordpress: Your attempt to edit this post has failed</a> (8)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/11/25/wordpress-265-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.6.1 released</title>
		<link>http://www.ghacks.net/2008/08/15/wordpress-261-released/</link>
		<comments>http://www.ghacks.net/2008/08/15/wordpress-261-released/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 12:00:59 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Online Services]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=6187</guid>
		<description><![CDATA[A new version of Wordpress has been released today and I&#8217;m currently in the process of updating all of my Wordpress blogs with the new version. That&#8217;s always a lot of work because I tend to prefer a manual update and not the automatic option that was implemented into Wordpress a while ago.
Over 60 fixes [...]]]></description>
			<content:encoded><![CDATA[<p>A new version of <a href="http://wordpress.org/development/2008/08/wordpress-261/">Wordpress</a> has been released today and I&#8217;m currently in the process of updating all of my Wordpress blogs with the new version. That&#8217;s always a lot of work because I tend to prefer a manual update and not the automatic option that was implemented into Wordpress a while ago.</p>
<p>Over 60 fixes have been introduced in the new Wordpress version, several of them critical and some security related. You can check out the complete list of fixes in Wordpress 2.6.1 by following the link to <a href="http://trac.wordpress.org/query?status=closed&#038;milestone=2.6.1&#038;resolution=fixed&#038;order=priority&#038;desc=1">Wordpress Trac</a>.</p>
<p>I&#8217;m usually not that interested in what has been fixed than to apply the updates to all of my blogs immediately. It does not look like as if new features have been introduced in Wordpress 2.6.1, more of a bug fix release it seems.</p>
<p><span id="more-6187"></span>The next big release will be Wordpress 2.7 which will introduce several new features and options to Wordpress. Looking forward to that. It is however recommended to update the blog as soon as possible.</p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/website/" title="website" rel="tag">website</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-security/" title="wordpress security" rel="tag">wordpress security</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/05/zoundry-raven-portable-blog-editor/" title="Zoundry Raven portable Blog Editor (August 5, 2008)">Zoundry Raven portable Blog Editor</a> (6)</li>
	<li><a href="http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/" title="Wordpress 2.8.6 Security Update (November 13, 2009)">Wordpress 2.8.6 Security Update</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/" title="Wordpress 2.8.5 Security Update (October 21, 2009)">Wordpress 2.8.5 Security Update</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/08/15/wordpress-261-released/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Scan your Wordpress blog for vulnerabilities</title>
		<link>http://www.ghacks.net/2007/07/09/scan-your-wordpress-blog-for-vulnerabilities/</link>
		<comments>http://www.ghacks.net/2007/07/09/scan-your-wordpress-blog-for-vulnerabilities/#comments</comments>
		<pubDate>Mon, 09 Jul 2007 07:33:31 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Online Services]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wordpress update]]></category>
		<category><![CDATA[wordpress vulnerabilites]]></category>
		<category><![CDATA[wp scanner]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/07/09/scan-your-wordpress-blog-for-vulnerabilities/</guid>
		<description><![CDATA[Site owners should always be aware of the possibility that their blog gets compromised. This can be because of an old version of Wordpress that is installed or because of vulnerabilities in plugins or themes. It is relatively time consuming to check for updates and stay up to date to make it unlikely that someone would be able to hack your blog.]]></description>
			<content:encoded><![CDATA[<p>Site owners should always be aware of the possibility that their blog gets compromised. This can be because of an old version of Wordpress that is installed or because of vulnerabilities in plugins or themes. It is relatively time consuming to check for updates and stay up to date to make it unlikely that someone would be able to hack your blog.</p>
<p>The online security script Wordpress Scanner is a great tool which can be used to scan your Wordpress blog for several vulnerabilities such as outdated versions of Wordpress or single files and XSS vulnerabilities in themes. All you need to do is add the line <code><!-- wpscanner --></code> in the header of your blog so that the <a href="http://blogsecurity.net/wpscan" target="_blank">Wordpress Scanner</a> cgi script can access the information and knows that you are indeed the owner of the blog.</p>
<p>This tool is not perfect but it analyzes the versions of your Wordpress files which is probably the dominant attack vector when it comes to Wordpress hacking and basic XSS vulnerabilities in the themes. The tool gives advice if vulnerabilities have been found on how to fix them.</p>
<p><span id="more-1753"></span>Just make sure you run the script, follow the guidelines and remove the wpscanner entry from your header again. You would not want someone else to be able to check your blog for vulnerabilities, would not you ? This is a great little script which should become even better when the author adds checks for plugins.</p>

	Tags: <a href="http://www.ghacks.net/tag/wordpress-security/" title="wordpress security" rel="tag">wordpress security</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a>, <a href="http://www.ghacks.net/tag/wordpress-vulnerabilites/" title="wordpress vulnerabilites" rel="tag">wordpress vulnerabilites</a>, <a href="http://www.ghacks.net/tag/wp-scanner/" title="wp scanner" rel="tag">wp scanner</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/" title="Wordpress 2.8.6 Security Update (November 13, 2009)">Wordpress 2.8.6 Security Update</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/" title="Wordpress 2.8.5 Security Update (October 21, 2009)">Wordpress 2.8.5 Security Update</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/15/wordpress-261-released/" title="Wordpress 2.6.1 released (August 15, 2008)">Wordpress 2.6.1 released</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/07/09/scan-your-wordpress-blog-for-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>
