- server-side request forgery vulnerability and remote port scanning using pingbacks (http://lab.onsec.ru/2013/01/wordpress-xmlrpc-pingback-additional.html) - cross-site scripting via shortcodes and post content - cross-site scripting vulnerability in the external library Plupload ok merdely@