<?xml version="1.0"?><!-- generator="bbPress" -->

<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
<title>Weblogtoolscollection News Topic: XSS vulnerability in WP Contact Form (III)</title>
<link>http://weblogtoolscollection.com/news/</link>
<description>Weblogtoolscollection News Topic: XSS vulnerability in WP Contact Form (III)</description>
<language>en</language>
<pubDate>Thu, 20 Jun 2013 01:44:44 +0000</pubDate>

<item>
<title>kzkw on "XSS vulnerability in WP Contact Form (III)"</title>
<link>http://weblogtoolscollection.com/news/topic/xss-vulnerability-in-wp-contact-form-iii#post-2243</link>
<pubDate>Sun, 03 Feb 2008 21:46:48 +0000</pubDate>
<dc:creator>kzkw</dc:creator>
<guid isPermaLink="false">2243@http://weblogtoolscollection.com/news/</guid>
<description>&#60;p&#62;I'm the author behind &#60;a href=&#34;http://wordpress.org/extend/plugins/wp-contact-form-iii/&#34;&#62;WP Contact Form III&#60;/a&#62; and someone discovered &#60;a href=&#34;http://www.hiredhacker.com/2008/02/02/xss-in-wp-contact-form-iii/&#34;&#62;XSS vulnerability&#60;/a&#62; in the plugin.&#60;/p&#62;
&#60;p&#62;My plugin and I think at least three other contact form plugins are based on &#60;a href=&#34;http://wordpress.org/extend/plugins/wp-contact-form/&#34;&#62;WP Contact Form&#60;/a&#62;, which also have the same code pointed out in the article on hiredhacker.com. &#60;/p&#62;
&#60;p&#62;I don't know if the other plugin authors who have used WP Contact Form as a base have fixed theirs, but at least mine and the original have the security issue.
&#60;/p&#62;</description>
</item>

</channel>
</rss>