<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent vulnerabilities from the mitre CNA root</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Latest vulnerabilities published by the CNAs operating under the mitre root of the CVE Program.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:10:16 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-97318 (WPScan)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-97318</link>
      <description>Giveaways and Contests by RafflePress &lt; 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter</description>
      <content:encoded>Giveaways and Contests by RafflePress &lt; 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-97318</guid>
      <pubDate>Fri, 02 Oct 2026 06:00:27 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-97317 (WPScan)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-97317</link>
      <description>Giveaways and Contests by RafflePress &lt; 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page</description>
      <content:encoded>Giveaways and Contests by RafflePress &lt; 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-97317</guid>
      <pubDate>Fri, 02 Oct 2026 06:00:26 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-94298 (WPScan)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-94298</link>
      <description>BuildKit &lt; 1.0.29 - Contributor+ Stored SQLi via list_content Parameter</description>
      <content:encoded>BuildKit &lt; 1.0.29 - Contributor+ Stored SQLi via list_content Parameter</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-94298</guid>
      <pubDate>Fri, 02 Oct 2026 06:00:26 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-91023 (WPScan)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-91023</link>
      <description>Motors – Car Dealership &amp; Classified Listings &lt; 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured</description>
      <content:encoded>Motors – Car Dealership &amp; Classified Listings &lt; 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-91023</guid>
      <pubDate>Fri, 02 Oct 2026 06:00:25 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-91022 (WPScan)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-91022</link>
      <description>Motors &lt; 1.4.124 - Listing Manager+ Stored XSS via Badge Color</description>
      <content:encoded>Motors &lt; 1.4.124 - Listing Manager+ Stored XSS via Badge Color</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-91022</guid>
      <pubDate>Fri, 02 Oct 2026 06:00:25 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-85016 (WPScan)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-85016</link>
      <description>Unlimited Elements For Elementor &lt; 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter</description>
      <content:encoded>Unlimited Elements For Elementor &lt; 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-85016</guid>
      <pubDate>Fri, 02 Oct 2026 06:00:25 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-91828 (WPScan)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-91828</link>
      <description>OMGF &lt; 6.3.11 - Unauthenticated DoS via do_optimize</description>
      <content:encoded>OMGF &lt; 6.3.11 - Unauthenticated DoS via do_optimize</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-91828</guid>
      <pubDate>Fri, 02 Oct 2026 06:00:25 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-13718 (WPScan)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-13718</link>
      <description>Tabs Responsive &lt;= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content</description>
      <content:encoded>Tabs Responsive &lt;= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-13718</guid>
      <pubDate>Fri, 02 Oct 2026 06:00:24 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-90988 (WPScan)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-90988</link>
      <description>Request a Quote &lt;= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum</description>
      <content:encoded>Request a Quote &lt;= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-90988</guid>
      <pubDate>Fri, 02 Oct 2026 06:00:24 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-85004 (WPScan)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-85004</link>
      <description>Popup Maker WP &lt;= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect</description>
      <content:encoded>Popup Maker WP &lt;= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-85004</guid>
      <pubDate>Fri, 02 Oct 2026 06:00:24 +0000</pubDate>
    </item>
  </channel>
</rss>
