<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 11:34:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-217724</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217724</link>
      <description>EUVD-2026-217724</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217724</guid>
    </item>
    <item>
      <title>fkie_cve-2021-39317</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-39317</link>
      <description>&lt;p&gt;A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer &amp;lt;=1.0.6 WordPress Themes: accesspress-basic &amp;lt;= 3.2.1 accesspress-lite &amp;lt;= 2.92 accesspress-mag &amp;lt;= 2.6.5 accesspress-parallax &amp;lt;= 4.5 accesspress-root &amp;lt;= 2.5 accesspress-store &amp;lt;= 2.4.9 agency-lite &amp;lt;= 1.1.6 arrival &amp;lt;= 1.4.2 bingle &amp;lt;= 1.0.4 bloger &amp;lt;= 1.2.6 brovy &amp;lt;= 1.3 construction-lite &amp;lt;= 1.2.5 doko &amp;lt;= 1.0.27 edict-lite &amp;lt;= 1.1.4 eightlaw-lite &amp;lt;= 2.1.5 eightmedi-lite &amp;lt;= 2.1.8 eight-sec &amp;lt;= 1.1.4 eightstore-lite &amp;lt;= 1.2.5 enlighten &amp;lt;= 1.3.5 fotography &amp;lt;= 2.4.0 opstore &amp;lt;= 1.4.3 parallaxsome &amp;lt;= 1.3.6 punte &amp;lt;= 1.1.2 revolve &amp;lt;= 1.3.1 ripple &amp;lt;= 1.2.0 sakala &amp;lt;= 1.0.4 scrollme &amp;lt;= 2.1.0 storevilla &amp;lt;= 1.4.1 swing-lite &amp;lt;= 1.1.9 the100 &amp;lt;= 1.1.2 the-launcher &amp;lt;= 1.3.2 the-monday &amp;lt;= 1.4.1 ultra-seven &amp;lt;= 1.2.8 uncode-lite &amp;lt;= 1.3.3 vmag &amp;lt;= 1.2.7 vmagazine-lite &amp;lt;= 1.3.5 vmagazine-news &amp;lt;= 1.0.5 wpparallax &amp;lt;= 2.0.6 wp-store &amp;lt;= 1.1.9 zigcy-baby &amp;lt;= 1.0.6 zigcy-cosmetics &amp;lt;= 1.0.5 zigcy-lite &amp;lt;= 2.0.9&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer &amp;lt;=1.0.6 WordPress Themes: accesspress-basic &amp;lt;= 3.2.1 accesspress-lite &amp;lt;= 2.92 accesspress-mag &amp;lt;= 2.6.5 accesspress-parallax &amp;lt;= 4.5 accesspress-root &amp;lt;= 2.5 accesspress-store &amp;lt;= 2.4.9 agency-lite &amp;lt;= 1.1.6 arrival &amp;lt;= 1.4.2 bingle &amp;lt;= 1.0.4 bloger &amp;lt;= 1.2.6 brovy &amp;lt;= 1.3 construction-lite &amp;lt;= 1.2.5 doko &amp;lt;= 1.0.27 edict-lite &amp;lt;= 1.1.4 eightlaw-lite &amp;lt;= 2.1.5 eightmedi-lite &amp;lt;= 2.1.8 eight-sec &amp;lt;= 1.1.4 eightstore-lite &amp;lt;= 1.2.5 enlighten &amp;lt;= 1.3.5 fotography &amp;lt;= 2.4.0 opstore &amp;lt;= 1.4.3 parallaxsome &amp;lt;= 1.3.6 punte &amp;lt;= 1.1.2 revolve &amp;lt;= 1.3.1 ripple &amp;lt;= 1.2.0 sakala &amp;lt;= 1.0.4 scrollme &amp;lt;= 2.1.0 storevilla &amp;lt;= 1.4.1 swing-lite &amp;lt;= 1.1.9 the100 &amp;lt;= 1.1.2 the-launcher &amp;lt;= 1.3.2 the-monday &amp;lt;= 1.4.1 ultra-seven &amp;lt;= 1.2.8 uncode-lite &amp;lt;= 1.3.3 vmag &amp;lt;= 1.2.7 vmagazine-lite &amp;lt;= 1.3.5 vmagazine-news &amp;lt;= 1.0.5 wpparallax &amp;lt;= 2.0.6 wp-store &amp;lt;= 1.1.9 zigcy-baby &amp;lt;= 1.0.6 zigcy-cosmetics &amp;lt;= 1.0.5 zigcy-lite &amp;lt;= 2.0.9&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-39317</guid>
    </item>
    <item>
      <title>GHSA-737m-cr75-9hw3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-737m-cr75-9hw3</link>
      <description>&lt;p&gt;Versions up to, and including, 1.0.6, of the Access Demo Importer WordPress plugin are vulnerable to arbitrary file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the ~/inc/demo-functions.php.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Versions up to, and including, 1.0.6, of the Access Demo Importer WordPress plugin are vulnerable to arbitrary file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the ~/inc/demo-functions.php.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-737m-cr75-9hw3</guid>
    </item>
    <item>
      <title>gsd-2021-39317</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-39317</link>
      <description>gsd-2021-39317</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-39317</guid>
    </item>
  </channel>
</rss>
