<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>WordPress on Omid Farhang</title><link>https://omid.dev/tags/wordpress/</link><description>Recent content in WordPress on Omid Farhang</description><image><title>Omid Farhang</title><url>https://omid.dev/images/bio-photo-150x150.jpg</url><link>https://omid.dev/images/bio-photo-150x150.jpg</link></image><generator>Hugo -- 0.163.3</generator><language>en-US</language><copyright>2026 Omid Farhang | All rights reserved.</copyright><lastBuildDate>Sun, 15 Jan 2023 23:55:43 +0330</lastBuildDate><atom:link href="https://omid.dev/tags/wordpress/index.xml" rel="self" type="application/rss+xml"/><item><title>Linux Malware targets WordPress and common Plugins</title><link>https://omid.dev/2023/01/16/linux-malware-targets-wordPress-and-common-plugins/</link><pubDate>Sun, 15 Jan 2023 23:55:43 +0330</pubDate><guid>https://omid.dev/2023/01/16/linux-malware-targets-wordPress-and-common-plugins/</guid><description>&lt;p&gt;Doctor Web has discovered a malicious Linux program that hacks websites based on a WordPress CMS. It exploits 30 vulnerabilities in a number of plugins and themes for this platform. If sites use outdated versions of such add-ons, lacking crucial fixes, the targeted webpages are injected with malicious JavaScripts. As a result, when users click on any area of an attacked page, they are redirected to other sites.&lt;/p&gt;
&lt;h2 id="what-they-can-do"&gt;What they can do?&lt;/h2&gt;
&lt;p&gt;Upon their command, it is able to perform the following actions:&lt;/p&gt;</description></item><item><title>WordPress hardened with XSS, DoS and SSRF fixes</title><link>https://omid.dev/2013/06/25/wordpress-hardened-with-xss-dos-and-ssrf-fixes/</link><pubDate>Tue, 25 Jun 2013 10:57:44 +0000</pubDate><guid>https://omid.dev/2013/06/25/wordpress-hardened-with-xss-dos-and-ssrf-fixes/</guid><description>&lt;p&gt;&lt;a href="https://omid.dev/images/2013/06/WordPress_grey_120.png"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2013/06/WordPress_grey_120.png" alt="WordPress" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;With the second security and maintenance release of WordPress 3.5, the developers of the popular open source blogging software have closed &lt;a href="http://core.trac.wordpress.org/query?status=closed&amp;amp;group=resolution&amp;amp;milestone=3.5.2"&gt;12 bugs&lt;/a&gt;, seven of them security issues. In their &lt;a href="http://wordpress.org/news/2013/06/wordpress-3-5-2/"&gt;announcement&lt;/a&gt;, the developers “strongly encourage” all users to update all their installations of the software to version 3.5.2 immediately. In addition to the fixed vulnerabilities, the new release also includes some proactive changes intended to harden the platform against attacks.&lt;/p&gt;</description></item><item><title>WordPress 3.4 update closes important security hole</title><link>https://omid.dev/2012/06/29/wordpress-3-4-update-closes-important-security-hole/</link><pubDate>Fri, 29 Jun 2012 19:57:00 +0000</pubDate><guid>https://omid.dev/2012/06/29/wordpress-3-4-update-closes-important-security-hole/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-SDHCMFQmafQ/T-4BsKNoSGI/AAAAAAAAGZI/4xH0Efd3_OA/s1600-h/WordPress%25255B2%25255D.png" alt="WordPress" /&gt;
&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://wordpress.org/"&gt;WordPress&lt;/a&gt; developers have &lt;a href="http://wordpress.org/news/2012/06/wordpress-3-4-1/"&gt;released&lt;/a&gt; version 3.4.1 of their popular open source publishing platform, fixing a number of bugs and closing security holes, one of which is rated as important. WordPress 3.4, which has already been downloaded 3 million times since being released two weeks ago, contains a important privilege escalation flaw that accidentally allowed all administrators and editors on multi-site installations to use &lt;a href="http://codex.wordpress.org/Roles_and_Capabilities#unfiltered_html"&gt;unfiltered_html&lt;/a&gt;. This could have been exploited by users for cross-site scripting (XSS) attacks by, for example, publishing posts containing malicious code.&lt;/p&gt;</description></item><item><title>WordPress fixes file upload security problems</title><link>https://omid.dev/2012/04/23/wordpress-fixes-file-upload-security-problems/</link><pubDate>Mon, 23 Apr 2012 18:52:00 +0000</pubDate><guid>https://omid.dev/2012/04/23/wordpress-fixes-file-upload-security-problems/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-h7QrTlJQ9tk/T5WdwJ55JfI/AAAAAAAAFmo/RxXwo8gHv00/s1600-h/WordPress_200%25255B3%25255D.png" alt="WordPress_200" /&gt;
&lt;/p&gt;
&lt;p&gt;The H-Security: The developers of the popular open source blog engine WordPress have &lt;a href="http://wordpress.org/news/2012/04/wordpress-3-3-2/"&gt;released&lt;/a&gt; a security update for the software. WordPress 3.3.2 fixes unspecified bugs in three external file upload libraries used in the software and other security problems with the application.&lt;/p&gt;
&lt;p&gt;The bugs affect both WordPress&amp;rsquo;s current file uploading library Plupload as well as the SWFUpload and SWFObject libraries; these were bundled with older versions of the application and might still be in use by certain plugins on the current versions of WordPress. The developers did not go into detail about the specifics of the security holes but thanked three people from the WordPress community for responsibly disclosing them. Three more fixes address a privilege escalation in the blog engine&amp;rsquo;s multi-site system and two cross-site scripting vulnerabilities in the core components of WordPress. More details on all of these patches and also some additional smaller fixes can be found in the &lt;a href="http://core.trac.wordpress.org/log/branches/3.3?rev=20552&amp;amp;stop_rev=20087"&gt;change log&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>WordPress.com suffers hacker attack – how to change your password</title><link>https://omid.dev/2011/04/14/wordpress-com-suffers-hacker-attack-how-to-change-your-password/</link><pubDate>Thu, 14 Apr 2011 07:32:00 +0000</pubDate><guid>https://omid.dev/2011/04/14/wordpress-com-suffers-hacker-attack-how-to-change-your-password/</guid><description>&lt;p&gt;&lt;a href="https://omid.dev/images/2011/04/wordpress-7a24556e.png"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2011/04/wordpress.png" alt="" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sophos Labs:&lt;/strong&gt; Millions of blog owners around the world are being advised to consider their password security, after WordPress.com was hacked.&lt;/p&gt;
&lt;p&gt;To its credit, Automattic – the company behind the WordPress.com blogging platform – didn&amp;rsquo;t mince its words or try to apply any spin to the incident, &lt;a href="http://en.blog.wordpress.com/2011/04/13/security/"&gt;explaining&lt;/a&gt; it had suffered a “low-level (root) break-in to several of [its] servers, and potentially anything on those servers could have been revealed.”&lt;/p&gt;</description></item><item><title>Follow up: Hacker Gains Access To WordPress.com Servers, Site Source Code Exposed</title><link>https://omid.dev/2011/04/13/follow-up-hacker-gains-access-to-wordpress-com-servers-site-source-code-exposed/</link><pubDate>Wed, 13 Apr 2011 23:18:00 +0000</pubDate><guid>https://omid.dev/2011/04/13/follow-up-hacker-gains-access-to-wordpress-com-servers-site-source-code-exposed/</guid><description>&lt;p&gt;Follow up from: &lt;a href="http://boelectronic.blogspot.com/2011/04/hacker-gains-access-to-wordpresscom.html"&gt;Hacker Gains Access To WordPress.com Servers&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://omid.dev/images/2011/04/wordpress-7a24556e.png"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2011/04/wordpress.png" alt="" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tech Crunch:&lt;/strong&gt; WordPress.com &lt;a href="http://en.blog.wordpress.com/2011/04/13/security/"&gt;has revealed&lt;/a&gt; that someone has gained root-access (“low-level,” as in deep) to several of its servers this morning and that VIP customers’ source code was accessible. WordPress.com VIP customers are all on “code red” and in the process of changing all the passwords/API keys they’ve left in the source code.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;“Tough note to communicate today: Automattic had a low-level (root) break-in to several of our servers, and potentially anything on those servers could have been revealed.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>Hacker Gains Access To WordPress.com Servers</title><link>https://omid.dev/2011/04/13/hacker-gains-access-to-wordpress-com-servers/</link><pubDate>Wed, 13 Apr 2011 17:51:00 +0000</pubDate><guid>https://omid.dev/2011/04/13/hacker-gains-access-to-wordpress-com-servers/</guid><description>&lt;p&gt;&lt;a href="https://omid.dev/images/2011/04/wordpress-7a24556e.png"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2011/04/wordpress.png" alt="" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tech Crunch:&lt;/strong&gt; WordPress.com has revealed that someone has gained access to several of the their servers this morning and that VIP customers’ source code was accessible. WordPress.com customers are all on ‘code red’ and in the process of changing all the passwords/api keys they’ve left in the source code.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;“Tough note to communicate today: Automattic had a low-level (root) break-in to several of our servers, and potentially anything on those servers could have been revealed.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>WordPress hit with second big attack in two days</title><link>https://omid.dev/2011/03/08/wordpress-hit-with-second-big-attack-in-two-days/</link><pubDate>Tue, 08 Mar 2011 11:31:00 +0000</pubDate><guid>https://omid.dev/2011/03/08/wordpress-hit-with-second-big-attack-in-two-days/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/_vaUVXcmC3OI/TXYMehLgrLI/AAAAAAAADm0/NIGbUdDoRYU/s1600-h/WordPressStats_610x431%5B3%5D.png" alt="WordPressStats_610x431" /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CNET wrote:&lt;/strong&gt; The popular blogging-site hoster &lt;a href="http://status.automattic.com/"&gt;WordPress&lt;/a&gt; was hit with another distributed denial-of-service attack this morning, the second in two days.&lt;/p&gt;
&lt;p&gt;“Unfortunately, the DDoS attack from yesterday returned in a different form this morning and affected sitewide performance,” the company said in a notice on its &lt;a href="http://status.automattic.com/"&gt;Automattic site&lt;/a&gt;, which serves as a dashboard for the service. “The good news is that we were able to mitigate it quickly and performance returned to normal around 11:15 &lt;a href="http://en.wikipedia.org/wiki/Coordinated_Universal_Time"&gt;UTC&lt;/a&gt;. We are continuing to monitor the situation closely.”&lt;/p&gt;</description></item><item><title>WordPress Adds Feature for Embedding Tweets</title><link>https://omid.dev/2010/11/06/wordpress-adds-feature-for-embedding-tweets/</link><pubDate>Sat, 06 Nov 2010 16:03:00 +0000</pubDate><guid>https://omid.dev/2010/11/06/wordpress-adds-feature-for-embedding-tweets/</guid><description>&lt;p&gt;&lt;strong&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/_vaUVXcmC3OI/TNV1NY2OnyI/AAAAAAAADFI/pTtT0Fc1OAg/s1600-h/twitter_logo_header%5B3%5D.png" alt="twitter_logo_header" /&gt;
Mashable&lt;/strong&gt;: Months ago, Twitter released a clunky tool called Blackbird Pie for embedding tweets in blog posts. Today WordPress has radically simplified and improved tweet embedding with a new feature, also named Twitter Blackbird Pie.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/_vaUVXcmC3OI/TNV1R-QlcdI/AAAAAAAADFQ/_Ma5CozoTao/s1600-h/icon_big%5B5%5D.png" alt="icon_big" /&gt;
&lt;/p&gt;
&lt;p&gt;Beginning today, WordPress.com users simply need to copy a tweet’s URL and paste it on a line by itself to embed it in a blog post.&lt;/p&gt;
&lt;p&gt;Pasted URLs are converted into full tweets, which means these embedded tweets look as good as screenshots, but include the link back to the tweet, a link to the source and a retweet option. The new feature will also save users time — letting them avoid the much more manual process of snapping screenshots of tweets.&lt;/p&gt;</description></item><item><title>Microsoft Kills Live Space blogs</title><link>https://omid.dev/2010/09/29/microsoft-kills-live-space-blogs/</link><pubDate>Wed, 29 Sep 2010 00:47:00 +0000</pubDate><guid>https://omid.dev/2010/09/29/microsoft-kills-live-space-blogs/</guid><description>&lt;p&gt;&lt;strong&gt;Microsoft&lt;/strong&gt; announced that it has collaborated with &lt;strong&gt;WordPress&lt;/strong&gt; and now onwards it will be the default blogging platform for Windows Live users. This means Microsoft is killing it’s own blogging platform and suggesting users to go for better platform called ‘WordPress’.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/_vaUVXcmC3OI/TKKFjAj9CDI/AAAAAAAACkA/37VMzIFp_BQ/s1600-h/8321.ConnectWordPress.comtoMessenger_thumb_5A730F1A%5B4%5D.jpg" alt="8321.ConnectWordPress.comtoMessenger_thumb_5A730F1A" /&gt;
&lt;/p&gt;
&lt;p&gt;In &lt;a href="http://disrupt.techcrunch.com/2010-sf/"&gt;TechCrunch Disrupt&lt;/a&gt; conference, Windows Live Director ‘Dharmesh Mehta’ announced that all existing &lt;a href="http://spaces.live.com/"&gt;Windows Live Spaces&lt;/a&gt; users will be migrated over to an account at &lt;a href="http://wordpress.com/"&gt;WordPress.com&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;So now onwards users who sign up for a Windows Live account get free Hotmail , the Xbox Live site , a free blog from WordPress.com and other services.&lt;/p&gt;</description></item><item><title>WordPress and PHP-based management systems under attack?</title><link>https://omid.dev/2010/05/11/wordpress-and-php-based-management-systems-under-attack/</link><pubDate>Tue, 11 May 2010 22:37:00 +0000</pubDate><guid>https://omid.dev/2010/05/11/wordpress-and-php-based-management-systems-under-attack/</guid><description>&lt;p&gt;A variety of sources are reporting that blog hosting sites with WordPress-created sites and php-based management systems such as Zen Care eCommerce are being infected with malicious scripts.&lt;/p&gt;
&lt;p&gt;Websites hosted by ISP DreamHost, GoDaddy, Bluehost and Media Temple have been found with the malcode, according to H-Online.com.&lt;/p&gt;
&lt;p&gt;The malicious scripts download malcode and block Google’s Safe Browsing API from alerting users.&lt;br&gt;
Story here: &lt;a href="http://www.h-online.com/security/news/item/Large-scale-attack-on-WordPress-996628.html"&gt;“Large-scale attack on WordPress”&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The Sucuri Security blog has offered clean-up instructions for those with infected pages &lt;a href="http://blog.sucuri.net/2010/05/simple-cleanup-solution-for-latest.html"&gt;here.&lt;/a&gt;&lt;/p&gt;</description></item><item><title>WordPress 3.0: The 5 Most Important New Features</title><link>https://omid.dev/2010/05/11/wordpress-3-0-the-5-most-important-new-features/</link><pubDate>Tue, 11 May 2010 13:53:00 +0000</pubDate><guid>https://omid.dev/2010/05/11/wordpress-3-0-the-5-most-important-new-features/</guid><description>&lt;p&gt;&lt;em&gt;Brian Casel is a web designer and owner of &lt;a href="http://themejam.com/"&gt;ThemeJam WordPress Themes&lt;/a&gt; and &lt;a href="http://casjam.com/"&gt;CasJam Media&lt;/a&gt;.  You can follow Brian on his blog at &lt;a href="http://www.briancasel.com/"&gt;briancasel.com&lt;/a&gt; or on Twitter &lt;a href="http://twitter.com/CasJam"&gt;@CasJam&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;WordPress has long been known as a dedicated blogging platform, giving users the tools they need to publish their message and interact with readers.  However, with the official release of version 3.0, set to drop this month, the platform will be much closer, if not well within the territory of a content management system (CMS).&lt;/p&gt;</description></item><item><title>WordPress Official App For iPad</title><link>https://omid.dev/2010/04/03/wordpress-official-app-for-ipad/</link><pubDate>Sat, 03 Apr 2010 12:31:00 +0000</pubDate><guid>https://omid.dev/2010/04/03/wordpress-official-app-for-ipad/</guid><description>&lt;p&gt;iPad apps seems to be getting more faster approved than apple iphone apps, we have seen many iPad apps being released. WordPress official app has been released for iPad today. As there lot more space on iPad for bloggers to write a web blog post through this wordpress app, this app seems to be useful.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://omid.dev/images/2010/04/WordpressforiPadscreenshots2-f2e8e2bd.jpg"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2010/04/WordpressforiPadscreenshots2.jpg" alt="" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;However it does not have any new features so it is just the iphone app being ported for iPad on apple ipad store, Below are some screenshots with which you can get the idea on how does this app will look like on iPad.&lt;/p&gt;</description></item></channel></rss>