Description
The WordPress Security white paper contains information including;
- An Overview of WordPress
- The WordPress Release Cycle
- Version Numbering and Security Releases
- Version Backwards Compatibility
- WordPress and Security
- WordPress Security Risks, Process, and History
- Automatic Background Updates for Security Releases
- 2013 OWASP Top 10
- A1 Injection
- A2 Broken Authentication and Session Management
- A3 Cross Site Scripting (XSS)
- A4 Insecure Direct Object Reference
- A5 Security Misconfiguration
- A6 Sensitive Data Exposure
- A7 Missing Function Level Access Control
- A8 Cross Site Request Forgery (CSRF)
- A9 Using Components with Known Vulnerabilities
- A10 Unvalidated Redirects and Forwards
- Further Security Risks and Concerns
- XXE (XML eXternal Entity) processing attacks
- SSRF (Server Side Request Forgery) Attacks
- WordPress Plugin and Theme Security
- The Default Theme
- The Role of the Hosting Provider in WordPress Security
- Core WordPress APIs
- Additional Reading
Reviews
There are no reviews yet.