<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spam Chronicles&#187; wordpress</title>
	<atom:link href="http://www.spamchronicles.com/tag/wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spamchronicles.com</link>
	<description>Chronicling My Spam Explorations</description>
	<lastBuildDate>Wed, 12 Sep 2007 02:11:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>WordPress Stats Plugin Vulnerability Plugged</title>
		<link>http://www.spamchronicles.com/2007/07/31/wordpress-stats-plugin-vulnerability-plugged/</link>
		<comments>http://www.spamchronicles.com/2007/07/31/wordpress-stats-plugin-vulnerability-plugged/#comments</comments>
		<pubDate>Tue, 31 Jul 2007 20:25:10 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/wordpress-stats-plugin-vulnerability-plugged/</guid>
		<description><![CDATA[I usually don&#8217;t mention WordPress vulnerabilities here, but since I use WordPress and the vulnerable plugin I figured I&#8217;d mention it (now that I&#8217;m patched). The WordPress Stats plugin by Automattic (Andy Skelton ) had a critical SQL injection vulnerability that could allow admin credentials to be stolen. The vulnerability was patched in version 1.1.1 [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spamchronicles.com/wp-content/uploads/2008/02/wp_logo2.png" title="WordPress Logo in Blue"><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/wp_logo2.png" alt="WordPress Logo in Blue" align="left" /></a>I usually don&#8217;t mention <b>WordPress </b>vulnerabilities here, but since I use WordPress and the vulnerable plugin I figured I&#8217;d mention it (now that I&#8217;m patched).</p>
<p>The <a href="http://wordpress.org/extend/plugins/stats/" title="Jump to the Plugin page on wordpress.org">WordPress Stats</a> plugin by Automattic (Andy Skelton ) had a critical SQL injection vulnerability that could allow admin credentials to be stolen. The vulnerability was patched in version 1.1.1 and was released July 27th.</p>
<p>I typically turn off (deactivate) plugins before updating them and in this case I had to re-enter the API key when activating the updated plugin.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/05/30/site-upgraded-to-wordpress-22/" rel="bookmark" class="crp_title">Site Upgraded to WordPress 2.2</a></li><li><a href="http://www.spamchronicles.com/2007/06/24/spam-counts-for-week-ending-june-24-2007/" rel="bookmark" class="crp_title">Spam Counts for Week Ending June 24, 2007</a></li><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/" rel="bookmark" class="crp_title">Mozilla Firefox 2.0.0.6 Released</a></li><li><a href="http://www.spamchronicles.com/2007/06/03/spam-counts-for-week-ending-june-3-2007/" rel="bookmark" class="crp_title">Spam Counts for Week Ending June 3, 2007</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/31/wordpress-stats-plugin-vulnerability-plugged/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Site Upgraded to WordPress 2.2</title>
		<link>http://www.spamchronicles.com/2007/05/30/site-upgraded-to-wordpress-22/</link>
		<comments>http://www.spamchronicles.com/2007/05/30/site-upgraded-to-wordpress-22/#comments</comments>
		<pubDate>Wed, 30 May 2007 14:48:12 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Site News]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/site-news/site-upgraded-to-wordpress-22/</guid>
		<description><![CDATA[The web site was upgraded to WordPress 2.2 last night. One of the changes made to WordPress 2.2 is that Widgets are now part of the core software and not enabled through a plugin. Widgets can be used on the sidebar and I do use them. The upgrade seems to have screwed up which widgets [...]]]></description>
			<content:encoded><![CDATA[<p>The web site was upgraded to <a title="Jump to the notification about WordPress 2..2 at wordpress.org" href="http://wordpress.org/development/2007/05/wordpress-22/">WordPress 2.2</a> last night. One of the changes made to WordPress 2.2 is that Widgets are now part of the core software and not enabled through a plugin. Widgets can be used on the sidebar and I do use them.</p>
<p>The upgrade seems to have screwed up which widgets are used on the sidebar. I&#8217;ve actually removed all widgets from the configuration so they might go away and the default sidebars will return. In any case, I&#8217;m planning a major site redesign from now until the weekend which will make the problem moot. [Update: The problem is unique to this theme - tiga 1.02 - which is <a href="http://codex.wordpress.org/Themes/Theme_Compatibility/2.2" title="Jump to the WordPress 2.2 Theme compatibility list">listed as non-compatible</a> so the problem should be resolved by the weekend when I change themes.]</p>
<p>Since I want to be at WordPress 2.2 for the upgrade I&#8217;m leaving things they way they are. <strike>Apologies for the slightly bizarre sidebars.</strike> [Updated 6/1 - with the theme update ths problem no longer exists]</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/31/wordpress-stats-plugin-vulnerability-plugged/" rel="bookmark" class="crp_title">WordPress Stats Plugin Vulnerability Plugged</a></li><li><a href="http://www.spamchronicles.com/2007/06/24/spam-counts-for-week-ending-june-24-2007/" rel="bookmark" class="crp_title">Spam Counts for Week Ending June 24, 2007</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/site-update/" rel="bookmark" class="crp_title">Site Update</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/" rel="bookmark" class="crp_title">Firefox 2.0.0.4 &#8211; Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/05/27/eight-anti-spam-tips/" rel="bookmark" class="crp_title">Eight Anti-Spam Tips</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/05/30/site-upgraded-to-wordpress-22/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
