<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/cna-root/mitre/recent</id>
  <title>Most recent vulnerabilities from the mitre CNA root</title>
  <updated>2026-10-02T07:10:16.065479+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Latest vulnerabilities published by the CNAs operating under the mitre root of the CVE Program.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-97318</id>
    <title>CVE-2026-97318 (WPScan)</title>
    <updated>2026-10-02T06:00:27.170000+00:00</updated>
    <content>Giveaways and Contests by RafflePress &lt; 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-97318"/>
    <summary>Giveaways and Contests by RafflePress &lt; 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter</summary>
    <published>2026-10-02T06:00:27.170000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-97317</id>
    <title>CVE-2026-97317 (WPScan)</title>
    <updated>2026-10-02T06:00:26.940000+00:00</updated>
    <content>Giveaways and Contests by RafflePress &lt; 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-97317"/>
    <summary>Giveaways and Contests by RafflePress &lt; 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page</summary>
    <published>2026-10-02T06:00:26.940000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-94298</id>
    <title>CVE-2026-94298 (WPScan)</title>
    <updated>2026-10-02T06:00:26.412000+00:00</updated>
    <content>BuildKit &lt; 1.0.29 - Contributor+ Stored SQLi via list_content Parameter</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-94298"/>
    <summary>BuildKit &lt; 1.0.29 - Contributor+ Stored SQLi via list_content Parameter</summary>
    <published>2026-10-02T06:00:26.412000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-91023</id>
    <title>CVE-2026-91023 (WPScan)</title>
    <updated>2026-10-02T06:00:25.876000+00:00</updated>
    <content>Motors – Car Dealership &amp; Classified Listings &lt; 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-91023"/>
    <summary>Motors – Car Dealership &amp; Classified Listings &lt; 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured</summary>
    <published>2026-10-02T06:00:25.876000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-91022</id>
    <title>CVE-2026-91022 (WPScan)</title>
    <updated>2026-10-02T06:00:25.652000+00:00</updated>
    <content>Motors &lt; 1.4.124 - Listing Manager+ Stored XSS via Badge Color</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-91022"/>
    <summary>Motors &lt; 1.4.124 - Listing Manager+ Stored XSS via Badge Color</summary>
    <published>2026-10-02T06:00:25.652000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-85016</id>
    <title>CVE-2026-85016 (WPScan)</title>
    <updated>2026-10-02T06:00:25.438000+00:00</updated>
    <content>Unlimited Elements For Elementor &lt; 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-85016"/>
    <summary>Unlimited Elements For Elementor &lt; 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter</summary>
    <published>2026-10-02T06:00:25.438000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-91828</id>
    <title>CVE-2026-91828 (WPScan)</title>
    <updated>2026-10-02T06:00:25.216000+00:00</updated>
    <content>OMGF &lt; 6.3.11 - Unauthenticated DoS via do_optimize</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-91828"/>
    <summary>OMGF &lt; 6.3.11 - Unauthenticated DoS via do_optimize</summary>
    <published>2026-10-02T06:00:25.216000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-13718</id>
    <title>CVE-2026-13718 (WPScan)</title>
    <updated>2026-10-02T06:00:24.997000+00:00</updated>
    <content>Tabs Responsive &lt;= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-13718"/>
    <summary>Tabs Responsive &lt;= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content</summary>
    <published>2026-10-02T06:00:24.997000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-90988</id>
    <title>CVE-2026-90988 (WPScan)</title>
    <updated>2026-10-02T06:00:24.780000+00:00</updated>
    <content>Request a Quote &lt;= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-90988"/>
    <summary>Request a Quote &lt;= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum</summary>
    <published>2026-10-02T06:00:24.780000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-85004</id>
    <title>CVE-2026-85004 (WPScan)</title>
    <updated>2026-10-02T06:00:24.239000+00:00</updated>
    <content>Popup Maker WP &lt;= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-85004"/>
    <summary>Popup Maker WP &lt;= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect</summary>
    <published>2026-10-02T06:00:24.239000+00:00</published>
  </entry>
</feed>
