<?xml version="1.0" encoding="UTF-8"?><!-- generator="bbPress" -->

<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
<title>WordPress &#8250; Support Topic: [Plugin: Vote It Up] Guest Exploit</title>
<link>http://wordpress.org/support/</link>
<description>WordPress &#8250; Support Topic: [Plugin: Vote It Up] Guest Exploit</description>
<language>en</language>
<pubDate>Tue, 24 Nov 2009 03:14:04 +0000</pubDate>

<item>
<title>preisjaeger on "[Plugin: Vote It Up] Guest Exploit"</title>
<link>http://wordpress.org/support/topic/264865#post-1166610</link>
<pubDate>Fri, 07 Aug 2009 12:54:54 +0000</pubDate>
<dc:creator>preisjaeger</dc:creator>
<guid isPermaLink="false">1166610@http://wordpress.org/support/</guid>
<description>&#60;p&#62;it was just a little copy&#38;amp;paste mistake (the wrong variables were given to GuestVoted() ). take a look in this GuestVote-function and you will see, that it's not correct using $post_ID and $user_ID for function GuestVoted(). It was also not escaped, so there was perhabs a little sercurity hole... ;)
&#60;/p&#62;</description>
</item>
<item>
<title>mightymendis on "[Plugin: Vote It Up] Guest Exploit"</title>
<link>http://wordpress.org/support/topic/264865#post-1098875</link>
<pubDate>Thu, 11 Jun 2009 16:22:10 +0000</pubDate>
<dc:creator>mightymendis</dc:creator>
<guid isPermaLink="false">1098875@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Thanks for this fix, preisjaeger.&#60;/p&#62;
&#60;p&#62;Can you, or someone else, explain how it fixes the exploit, please?
&#60;/p&#62;</description>
</item>
<item>
<title>preisjaeger on "[Plugin: Vote It Up] Guest Exploit"</title>
<link>http://wordpress.org/support/topic/264865#post-1083516</link>
<pubDate>Tue, 26 May 2009 09:07:29 +0000</pubDate>
<dc:creator>preisjaeger</dc:creator>
<guid isPermaLink="false">1083516@http://wordpress.org/support/</guid>
<description>&#60;p&#62;Here is my bugfix to this issue (with your description): &#60;a href=&#34;http://www.preisjaeger.at/news/bugfix-in-wp-plugin-vote-it-up-multiple-voting-for-guests/&#34; rel=&#34;nofollow&#34;&#62;http://www.preisjaeger.at/news/bugfix-in-wp-plugin-vote-it-up-multiple-voting-for-guests/&#60;/a&#62;
&#60;/p&#62;</description>
</item>
<item>
<title>okaysamurai on "[Plugin: Vote It Up] Guest Exploit"</title>
<link>http://wordpress.org/support/topic/264865#post-1054985</link>
<pubDate>Fri, 24 Apr 2009 05:23:38 +0000</pubDate>
<dc:creator>okaysamurai</dc:creator>
<guid isPermaLink="false">1054985@http://wordpress.org/support/</guid>
<description>&#60;p&#62;A word of warning: if you select the option to let guests vote, there is an exploit that allows users to vote multiple times. If you click &#34;vote&#34; once, no problem. But if you click &#34;vote&#34; rapidly and repeatedly, it will count every click until it changes to a &#34;voted&#34; state - thus allowing one user to vote multiple times.&#60;/p&#62;
&#60;p&#62;As it stands, you should only use this plugin with required registration.&#60;/p&#62;
&#60;p&#62;A small but critical bug in an otherwise awesome plugin!
&#60;/p&#62;</description>
</item>

</channel>
</rss>
