<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T12:37:15.293811+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-5149</id>
    <title>CVE-2024-5149 — BuddyForms &lt;= 2.8.9 - Email Verification Bypass due to Insufficient Randomness</title>
    <updated>2026-10-08T12:37:15.294858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> themekraft Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC), themekraft post_form_registration_form_profile_form_for_user_profiles_and_content_forms</p>
<p>The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-5149"/>
  </entry>
</feed>
