<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Prevent CVE-2018-6389 exploit on your WordPress powered website	</title>
	<atom:link href="https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/</link>
	<description>Premium Plugins for WordPress and bbPress</description>
	<lastBuildDate>Wed, 14 Dec 2022 09:44:17 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>
	<item>
		<title>
		By: Milan Petrovic		</title>
		<link>https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1322924</link>

		<dc:creator><![CDATA[Milan Petrovic]]></dc:creator>
		<pubDate>Wed, 14 Dec 2022 09:44:17 +0000</pubDate>
		<guid isPermaLink="false">https://www.dev4press.com/?p=32168/#comment-1322924</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1322919&quot;&gt;Ashiquer kagozi&lt;/a&gt;.

As far as I know, no.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1322919">Ashiquer kagozi</a>.</p>
<p>As far as I know, no.</p>

<div class="gdrts-dynamic-block">

	<script class="gdrts-rating-data" type="application/json">{"args":{"echo":false,"entity":"comments","name":"comment","item_id":null,"id":"1322924","method":"like-this","series":null,"disable_dynamic_load":false,"dynamic":true},"method":{"disable_rating":false,"allow_super_admin":true,"allow_user_roles":["administrator","editor","author","contributor","subscriber","customer","bbp_keymaster","bbp_spectator","bbp_blocked","bbp_moderator","bbp_participant","support","system"],"allow_visitor":true,"allow_author":true,"votes_count_compact_show":true,"votes_count_compact_decimals":1,"cta":"","template":"feed","rating":"sum","alignment":"none","style_type":"font","style_name":"hands-fill","style_theme":"expanding","style_size":20,"style_class":"","labels":{"like":"Like","liked":"Liked","unlike":"Unlike"}}}</script>
    <div class="gdrts-rating-please-wait">
        <i class="rtsicon-spinner rtsicon-spin rtsicon-va rtsicon-fw"></i> Please wait...    </div>

	
</div>]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Ashiquer kagozi		</title>
		<link>https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1322919</link>

		<dc:creator><![CDATA[Ashiquer kagozi]]></dc:creator>
		<pubDate>Mon, 12 Dec 2022 11:50:34 +0000</pubDate>
		<guid isPermaLink="false">https://www.dev4press.com/?p=32168/#comment-1322919</guid>

					<description><![CDATA[is this vulnerability still exist in recent WordPress version 6. X?]]></description>
			<content:encoded><![CDATA[<p>is this vulnerability still exist in recent WordPress version 6. X?</p>

<div class="gdrts-dynamic-block">

	<script class="gdrts-rating-data" type="application/json">{"args":{"echo":false,"entity":"comments","name":"comment","item_id":null,"id":"1322919","method":"like-this","series":null,"disable_dynamic_load":false,"dynamic":true},"method":{"disable_rating":false,"allow_super_admin":true,"allow_user_roles":["administrator","editor","author","contributor","subscriber","customer","bbp_keymaster","bbp_spectator","bbp_blocked","bbp_moderator","bbp_participant","support","system"],"allow_visitor":true,"allow_author":true,"votes_count_compact_show":true,"votes_count_compact_decimals":1,"cta":"","template":"feed","rating":"sum","alignment":"none","style_type":"font","style_name":"hands-fill","style_theme":"expanding","style_size":20,"style_class":"","labels":{"like":"Like","liked":"Liked","unlike":"Unlike"}}}</script>
    <div class="gdrts-rating-please-wait">
        <i class="rtsicon-spinner rtsicon-spin rtsicon-va rtsicon-fw"></i> Please wait...    </div>

	
</div>]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: MillaN		</title>
		<link>https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1292457</link>

		<dc:creator><![CDATA[MillaN]]></dc:creator>
		<pubDate>Wed, 31 Oct 2018 13:28:08 +0000</pubDate>
		<guid isPermaLink="false">https://www.dev4press.com/?p=32168/#comment-1292457</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1292456&quot;&gt;Derbat&lt;/a&gt;.

Can you explain?]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1292456">Derbat</a>.</p>
<p>Can you explain?</p>

<div class="gdrts-dynamic-block">

	<script class="gdrts-rating-data" type="application/json">{"args":{"echo":false,"entity":"comments","name":"comment","item_id":null,"id":"1292457","method":"like-this","series":null,"disable_dynamic_load":false,"dynamic":true},"method":{"disable_rating":false,"allow_super_admin":true,"allow_user_roles":["administrator","editor","author","contributor","subscriber","customer","bbp_keymaster","bbp_spectator","bbp_blocked","bbp_moderator","bbp_participant","support","system"],"allow_visitor":true,"allow_author":true,"votes_count_compact_show":true,"votes_count_compact_decimals":1,"cta":"","template":"feed","rating":"sum","alignment":"none","style_type":"font","style_name":"hands-fill","style_theme":"expanding","style_size":20,"style_class":"","labels":{"like":"Like","liked":"Liked","unlike":"Unlike"}}}</script>
    <div class="gdrts-rating-please-wait">
        <i class="rtsicon-spinner rtsicon-spin rtsicon-va rtsicon-fw"></i> Please wait...    </div>

	
</div>]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Derbat		</title>
		<link>https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1292456</link>

		<dc:creator><![CDATA[Derbat]]></dc:creator>
		<pubDate>Wed, 31 Oct 2018 13:17:36 +0000</pubDate>
		<guid isPermaLink="false">https://www.dev4press.com/?p=32168/#comment-1292456</guid>

					<description><![CDATA[Hi everyone. I have a trouble with it]]></description>
			<content:encoded><![CDATA[<p>Hi everyone. I have a trouble with it</p>

<div class="gdrts-dynamic-block">

	<script class="gdrts-rating-data" type="application/json">{"args":{"echo":false,"entity":"comments","name":"comment","item_id":null,"id":"1292456","method":"like-this","series":null,"disable_dynamic_load":false,"dynamic":true},"method":{"disable_rating":false,"allow_super_admin":true,"allow_user_roles":["administrator","editor","author","contributor","subscriber","customer","bbp_keymaster","bbp_spectator","bbp_blocked","bbp_moderator","bbp_participant","support","system"],"allow_visitor":true,"allow_author":true,"votes_count_compact_show":true,"votes_count_compact_decimals":1,"cta":"","template":"feed","rating":"sum","alignment":"none","style_type":"font","style_name":"hands-fill","style_theme":"expanding","style_size":20,"style_class":"","labels":{"like":"Like","liked":"Liked","unlike":"Unlike"}}}</script>
    <div class="gdrts-rating-please-wait">
        <i class="rtsicon-spinner rtsicon-spin rtsicon-va rtsicon-fw"></i> Please wait...    </div>

	
</div>]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Jon		</title>
		<link>https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1290821</link>

		<dc:creator><![CDATA[Jon]]></dc:creator>
		<pubDate>Tue, 20 Feb 2018 16:37:22 +0000</pubDate>
		<guid isPermaLink="false">https://www.dev4press.com/?p=32168/#comment-1290821</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1290819&quot;&gt;Jon&lt;/a&gt;.

Hmmm....the code in &#039;greater than&#039; and &#039;less than&#039; was stripped from my reply. It should be (without the symbols) :

FilesMatch &quot;wp-admin/load-scripts\.php&#124;wp-admin/load-styles\.php&quot;
  Order allow,deny
  Deny from all
/FilesMatch]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1290819">Jon</a>.</p>
<p>Hmmm&#8230;.the code in &#8216;greater than&#8217; and &#8216;less than&#8217; was stripped from my reply. It should be (without the symbols) :</p>
<p>FilesMatch &#8220;wp-admin/load-scripts\.php|wp-admin/load-styles\.php&#8221;<br />
  Order allow,deny<br />
  Deny from all<br />
/FilesMatch</p>

<div class="gdrts-dynamic-block">

	<script class="gdrts-rating-data" type="application/json">{"args":{"echo":false,"entity":"comments","name":"comment","item_id":null,"id":"1290821","method":"like-this","series":null,"disable_dynamic_load":false,"dynamic":true},"method":{"disable_rating":false,"allow_super_admin":true,"allow_user_roles":["administrator","editor","author","contributor","subscriber","customer","bbp_keymaster","bbp_spectator","bbp_blocked","bbp_moderator","bbp_participant","support","system"],"allow_visitor":true,"allow_author":true,"votes_count_compact_show":true,"votes_count_compact_decimals":1,"cta":"","template":"feed","rating":"sum","alignment":"none","style_type":"font","style_name":"hands-fill","style_theme":"expanding","style_size":20,"style_class":"","labels":{"like":"Like","liked":"Liked","unlike":"Unlike"}}}</script>
    <div class="gdrts-rating-please-wait">
        <i class="rtsicon-spinner rtsicon-spin rtsicon-va rtsicon-fw"></i> Please wait...    </div>

	
</div>]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: MillaN		</title>
		<link>https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1290820</link>

		<dc:creator><![CDATA[MillaN]]></dc:creator>
		<pubDate>Tue, 20 Feb 2018 16:36:44 +0000</pubDate>
		<guid isPermaLink="false">https://www.dev4press.com/?p=32168/#comment-1290820</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1290819&quot;&gt;Jon&lt;/a&gt;.

Without concatenation disabled, WordPress still attempts to use load-script.php and load-styles.php file. Maybe due to the cache in browser you still don&#039;t have issues, or something else has disabled concatenation on your website (maybe you have some plugin that did that).]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1290819">Jon</a>.</p>
<p>Without concatenation disabled, WordPress still attempts to use load-script.php and load-styles.php file. Maybe due to the cache in browser you still don&#8217;t have issues, or something else has disabled concatenation on your website (maybe you have some plugin that did that).</p>

<div class="gdrts-dynamic-block">

	<script class="gdrts-rating-data" type="application/json">{"args":{"echo":false,"entity":"comments","name":"comment","item_id":null,"id":"1290820","method":"like-this","series":null,"disable_dynamic_load":false,"dynamic":true},"method":{"disable_rating":false,"allow_super_admin":true,"allow_user_roles":["administrator","editor","author","contributor","subscriber","customer","bbp_keymaster","bbp_spectator","bbp_blocked","bbp_moderator","bbp_participant","support","system"],"allow_visitor":true,"allow_author":true,"votes_count_compact_show":true,"votes_count_compact_decimals":1,"cta":"","template":"feed","rating":"sum","alignment":"none","style_type":"font","style_name":"hands-fill","style_theme":"expanding","style_size":20,"style_class":"","labels":{"like":"Like","liked":"Liked","unlike":"Unlike"}}}</script>
    <div class="gdrts-rating-please-wait">
        <i class="rtsicon-spinner rtsicon-spin rtsicon-va rtsicon-fw"></i> Please wait...    </div>

	
</div>]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Jon		</title>
		<link>https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1290819</link>

		<dc:creator><![CDATA[Jon]]></dc:creator>
		<pubDate>Tue, 20 Feb 2018 16:33:22 +0000</pubDate>
		<guid isPermaLink="false">https://www.dev4press.com/?p=32168/#comment-1290819</guid>

					<description><![CDATA[Ta very much for the additional explanation. Odd that I have used this in .htaccess:

  Order allow,deny
  Deny from all

...but not added the option to disable concatenation and I have no problems with the admin area and the exploit no longer works when I test it.

Thanks again, I&#039;ll make sure that I disable concatenation anyway...just to be sure!]]></description>
			<content:encoded><![CDATA[<p>Ta very much for the additional explanation. Odd that I have used this in .htaccess:</p>
<p>  Order allow,deny<br />
  Deny from all</p>
<p>&#8230;but not added the option to disable concatenation and I have no problems with the admin area and the exploit no longer works when I test it.</p>
<p>Thanks again, I&#8217;ll make sure that I disable concatenation anyway&#8230;just to be sure!</p>

<div class="gdrts-dynamic-block">

	<script class="gdrts-rating-data" type="application/json">{"args":{"echo":false,"entity":"comments","name":"comment","item_id":null,"id":"1290819","method":"like-this","series":null,"disable_dynamic_load":false,"dynamic":true},"method":{"disable_rating":false,"allow_super_admin":true,"allow_user_roles":["administrator","editor","author","contributor","subscriber","customer","bbp_keymaster","bbp_spectator","bbp_blocked","bbp_moderator","bbp_participant","support","system"],"allow_visitor":true,"allow_author":true,"votes_count_compact_show":true,"votes_count_compact_decimals":1,"cta":"","template":"feed","rating":"sum","alignment":"none","style_type":"font","style_name":"hands-fill","style_theme":"expanding","style_size":20,"style_class":"","labels":{"like":"Like","liked":"Liked","unlike":"Unlike"}}}</script>
    <div class="gdrts-rating-please-wait">
        <i class="rtsicon-spinner rtsicon-spin rtsicon-va rtsicon-fw"></i> Please wait...    </div>

	
</div>]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: MillaN		</title>
		<link>https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1290818</link>

		<dc:creator><![CDATA[MillaN]]></dc:creator>
		<pubDate>Tue, 20 Feb 2018 16:12:01 +0000</pubDate>
		<guid isPermaLink="false">https://www.dev4press.com/?p=32168/#comment-1290818</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1290817&quot;&gt;Jon&lt;/a&gt;.

Thanks for the comment Jon! If you don&#039;t disable concatenation, WordPress will attempt to use it on the admin side, and pages loading will fail. Cache plugins usually work for the front end (not admin side), so concatenation options is not affecting them. I use WP Rocket plugin, and it works fine.

For this to work both .htaccess code and disabling of concatenation must be applied.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1290817">Jon</a>.</p>
<p>Thanks for the comment Jon! If you don&#8217;t disable concatenation, WordPress will attempt to use it on the admin side, and pages loading will fail. Cache plugins usually work for the front end (not admin side), so concatenation options is not affecting them. I use WP Rocket plugin, and it works fine.</p>
<p>For this to work both .htaccess code and disabling of concatenation must be applied.</p>

<div class="gdrts-dynamic-block">

	<script class="gdrts-rating-data" type="application/json">{"args":{"echo":false,"entity":"comments","name":"comment","item_id":null,"id":"1290818","method":"like-this","series":null,"disable_dynamic_load":false,"dynamic":true},"method":{"disable_rating":false,"allow_super_admin":true,"allow_user_roles":["administrator","editor","author","contributor","subscriber","customer","bbp_keymaster","bbp_spectator","bbp_blocked","bbp_moderator","bbp_participant","support","system"],"allow_visitor":true,"allow_author":true,"votes_count_compact_show":true,"votes_count_compact_decimals":1,"cta":"","template":"feed","rating":"sum","alignment":"none","style_type":"font","style_name":"hands-fill","style_theme":"expanding","style_size":20,"style_class":"","labels":{"like":"Like","liked":"Liked","unlike":"Unlike"}}}</script>
    <div class="gdrts-rating-please-wait">
        <i class="rtsicon-spinner rtsicon-spin rtsicon-va rtsicon-fw"></i> Please wait...    </div>

	
</div>]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Jon		</title>
		<link>https://www.dev4press.com/blog/tutorials/2018/prevent-cve-2018-6389-exploit-on-your-wordpress-powered-website/#comment-1290817</link>

		<dc:creator><![CDATA[Jon]]></dc:creator>
		<pubDate>Tue, 20 Feb 2018 15:50:51 +0000</pubDate>
		<guid isPermaLink="false">https://www.dev4press.com/?p=32168/#comment-1290817</guid>

					<description><![CDATA[Thanks for this - very helpful and simple to implement. One question though: if access to the files is prevented via .htaccess, is there any need to disable concatenation via wp-config.php? Having added the rule to my .htaccess file, but not disabled concatenation, the exploit no longer works. I use a caching plugin (WT3C - with HTTP/2 enabled) that combines .js and css for better page speed. If I disable concatenation will that not affect this caching option?]]></description>
			<content:encoded><![CDATA[<p>Thanks for this &#8211; very helpful and simple to implement. One question though: if access to the files is prevented via .htaccess, is there any need to disable concatenation via wp-config.php? Having added the rule to my .htaccess file, but not disabled concatenation, the exploit no longer works. I use a caching plugin (WT3C &#8211; with HTTP/2 enabled) that combines .js and css for better page speed. If I disable concatenation will that not affect this caching option?</p>

<div class="gdrts-dynamic-block">

	<script class="gdrts-rating-data" type="application/json">{"args":{"echo":false,"entity":"comments","name":"comment","item_id":null,"id":"1290817","method":"like-this","series":null,"disable_dynamic_load":false,"dynamic":true},"method":{"disable_rating":false,"allow_super_admin":true,"allow_user_roles":["administrator","editor","author","contributor","subscriber","customer","bbp_keymaster","bbp_spectator","bbp_blocked","bbp_moderator","bbp_participant","support","system"],"allow_visitor":true,"allow_author":true,"votes_count_compact_show":true,"votes_count_compact_decimals":1,"cta":"","template":"feed","rating":"sum","alignment":"none","style_type":"font","style_name":"hands-fill","style_theme":"expanding","style_size":20,"style_class":"","labels":{"like":"Like","liked":"Liked","unlike":"Unlike"}}}</script>
    <div class="gdrts-rating-please-wait">
        <i class="rtsicon-spinner rtsicon-spin rtsicon-va rtsicon-fw"></i> Please wait...    </div>

	
</div>]]></content:encoded>
		
			</item>
	</channel>
</rss>
