<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T00:27:19.159839+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-250564</id>
    <title>EUVD-2026-250564</title>
    <updated>2026-10-07T00:27:19.163099+00:00</updated>
    <content>EUVD-2026-250564</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-250564"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-8678</id>
    <title>fkie_cve-2025-8678</title>
    <updated>2026-10-07T00:27:19.163147+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via the 'wp_remote_request' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-8678"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-35c5-67fm-cpcp</id>
    <title>GHSA-35c5-67fm-cpcp — WP Crontrol Authenticated (Administrator+) plugin vulnerable to Blind Server-Side Request Forgery</title>
    <updated>2026-10-07T00:27:19.163197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: johnbillion/wp-crontrol</p>
<p>### Impact</p>
<p>The WP Crontrol plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via the `wp_remote_request()` function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.</p>
<p>It is not possible for a user without Administrator level access to exploit this weakness. It is not possible for an Administrator performing an attack to see the HTTP response to the request to their chosen URL, nor is it possible for them to time the response.</p>
<p>### Patches</p>
<p>WP Crontrol version 1.19.2 makes the following changes to harden the URL cron event feature:</p>
<p>* URLs are now validated for safety with the `wp_http_validate_url()` function upon saving. The user is informed if they save a cron event containing a URL that is not considered safe, and the HTTP request will not trigger when the event runs.
* HTTP requests are now performed via the `wp_safe_remote_request()` function in place of `wp_remote_request()`. This prevents an SSRF being performed.</p>
<p>### Workarounds</p>
<p>Update the WP Crontrol plugin for WordPress to version 1.19.2 or later. If you are not able to update immediately, remove any Administrator level users who are not fully trusted.</p>
<p>### FAQ</p>
<p>#### Is my site at risk?</p>
<p>Your site is only at risk if an untrustworthy Administrator on your site decides…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-35c5-67fm-cpcp"/>
  </entry>
</feed>
