Wordpress XSS Vulnerabilities

Beni has been busy lately, doing what he does best: identifying vulnerabilities, security flaws, XSS exploits, etc.

In the last few days he’s been playing with Wordpress and identified no less than 7 vulnerabilities and he even created a friendly worm to disclose certain flaws.

Wordpress Zero-Day Vulnerability

Wordpress XSS Worm

And can you believe Beni is only 18! Bright kid, bright future and I’m surprised no-one has snapped-up his talents yet!

4

newcleus says:
Aug 1, 2007 - 10:08:10

off to hijack a few pr 9 blogs.

Aug 8, 2007 - 11:08:20

these are some awesome exploits….yup im off to do the same thing lol!

Nov 18, 2007 - 08:11:42

I was chasing girls at 18. Wish I had been as focused as him at his age. Nice…

On a side note: I stumbled across this blog through a google custom search engine and I must say I like this blog better than bluehatseo.com or black-hat. Keep up the quality informations and better how-to’s and I’ll be back frequently.

Jess says:
Feb 24, 2010 - 08:02:31

As for me, I am using this tool for preventing XSS disasters:
http://xss-scanner.com

*
To prove you're a person (and not a spam bot - although we do like cute bots round here), type the security word shown in the picture.
Anti-Spam Image