<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 18:29:02 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-86851 — Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Change, Order Note Injection &amp; Order Key Disclosure</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-86851</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Livees Checkout&lt;/p&gt;
&lt;p&gt;The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-key check before acting on request parameters on the order confirmation page, allowing unauthenticated users to change the status of arbitrary orders, store arbitrary data and notes on them, and recover their order keys.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Livees Checkout&lt;/p&gt;
&lt;p&gt;The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-key check before acting on request parameters on the order confirmation page, allowing unauthenticated users to change the status of arbitrary orders, store arbitrary data and notes on them, and recover their order keys.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-86851</guid>
    </item>
  </channel>
</rss>
