<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress vulnerability means don&#8217;t save sensitive information in drafts</title>
	<atom:link href="http://wpgarage.com/news-views/wordpress-vulnerability-means-dont-save-sensitive-information-in-drafts/feed/" rel="self" type="application/rss+xml" />
	<link>http://wpgarage.com/news-views/wordpress-vulnerability-means-dont-save-sensitive-information-in-drafts/</link>
	<description>wordpress tricks, hacks, and tips</description>
	<lastBuildDate>Wed, 09 May 2012 06:53:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: It&#8217;s time to upgrade WordPress &#124; WordPressGarage.com</title>
		<link>http://wpgarage.com/news-views/wordpress-vulnerability-means-dont-save-sensitive-information-in-drafts/#comment-760</link>
		<dc:creator>It&#8217;s time to upgrade WordPress &#124; WordPressGarage.com</dc:creator>
		<pubDate>Sun, 30 Dec 2007 11:08:33 +0000</pubDate>
		<guid isPermaLink="false">http://wordpressgarage.com/news-views/wordpress-vulnerability-means-dont-save-sensitive-information-in-drafts/#comment-760</guid>
		<description>[...] releasing any new versions until 2.3, we now are faced with WordPress version 2.3.2, which fixes the draft vulnerability we wrote about recently, as well as &#8220;suppress[ing] some error messages that can give away [...]</description>
		<content:encoded><![CDATA[<p>[...] releasing any new versions until 2.3, we now are faced with WordPress version 2.3.2, which fixes the draft vulnerability we wrote about recently, as well as &#8220;suppress[ing] some error messages that can give away [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://wpgarage.com/news-views/wordpress-vulnerability-means-dont-save-sensitive-information-in-drafts/#comment-759</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Thu, 20 Dec 2007 19:51:29 +0000</pubDate>
		<guid isPermaLink="false">http://wordpressgarage.com/news-views/wordpress-vulnerability-means-dont-save-sensitive-information-in-drafts/#comment-759</guid>
		<description>I think the main reason for WordPress security updates and reports being so common is due to it&#039;s popularity. More people using it means more people finding holes and more people trying to take advantage of holes.

The thing is though ... who cares if drafts are in insecure? Surely no one would store particularly sensitive information in them?

The only way I could see this being a problem is if sploggers managed to access them and posted them before you did, which could potentially lead to your content being picked up as a duplicate of the splogger instead of the other way around due to theirs being published first.

I read recently that WordPress have no intentions of an update until 2.4 is released some time in January/February. So maybe they&#039;ll stick to that schedule.</description>
		<content:encoded><![CDATA[<p>I think the main reason for WordPress security updates and reports being so common is due to it&#8217;s popularity. More people using it means more people finding holes and more people trying to take advantage of holes.</p>
<p>The thing is though &#8230; who cares if drafts are in insecure? Surely no one would store particularly sensitive information in them?</p>
<p>The only way I could see this being a problem is if sploggers managed to access them and posted them before you did, which could potentially lead to your content being picked up as a duplicate of the splogger instead of the other way around due to theirs being published first.</p>
<p>I read recently that WordPress have no intentions of an update until 2.4 is released some time in January/February. So maybe they&#8217;ll stick to that schedule.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

