<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/cvelistv5/10</id>
  <title>Most recent entries from cvelistv5</title>
  <updated>2026-10-02T07:10:19.606010+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-97318</id>
    <title>CVE-2026-97318 — Giveaways and Contests by RafflePress &lt; 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter</title>
    <updated>2026-10-02T06:00:27.170000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown Giveaways and Contests by RafflePress</p>
<p>The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-97318"/>
    <published>2026-10-02T06:00:27.170000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-97317</id>
    <title>CVE-2026-97317 — Giveaways and Contests by RafflePress &lt; 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page</title>
    <updated>2026-10-02T06:00:26.940000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown Giveaways and Contests by RafflePress</p>
<p>The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-97317"/>
    <published>2026-10-02T06:00:26.940000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-94298</id>
    <title>CVE-2026-94298 — BuildKit &lt; 1.0.29 - Contributor+ Stored SQLi via list_content Parameter</title>
    <updated>2026-10-02T06:00:26.412000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown BuildKit</p>
<p>The BuildKit  WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-94298"/>
    <published>2026-10-02T06:00:26.412000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-91023</id>
    <title>CVE-2026-91023 — Motors – Car Dealership &amp; Classified Listings &lt; 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_fe…</title>
    <updated>2026-10-02T06:00:25.876000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown Motors</p>
<p>The Motors  WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors  WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-91023"/>
    <published>2026-10-02T06:00:25.876000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-91022</id>
    <title>CVE-2026-91022 — Motors &lt; 1.4.124 - Listing Manager+ Stored XSS via Badge Color</title>
    <updated>2026-10-02T06:00:25.652000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown Motors</p>
<p>The Motors  WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-91022"/>
    <published>2026-10-02T06:00:25.652000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-85016</id>
    <title>CVE-2026-85016 — Unlimited Elements For Elementor &lt; 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter</title>
    <updated>2026-10-02T06:00:25.438000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown Unlimited Elements for Elementor</p>
<p>The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-85016"/>
    <published>2026-10-02T06:00:25.438000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-91828</id>
    <title>CVE-2026-91828 — OMGF &lt; 6.3.11 - Unauthenticated DoS via do_optimize</title>
    <updated>2026-10-02T06:00:25.216000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.</p>
<p>The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-91828"/>
    <published>2026-10-02T06:00:25.216000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-13718</id>
    <title>CVE-2026-13718 — Tabs Responsive &lt;= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content</title>
    <updated>2026-10-02T06:00:24.997000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown Tabs Responsive</p>
<p>The Tabs Responsive  WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-13718"/>
    <published>2026-10-02T06:00:24.997000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-90988</id>
    <title>CVE-2026-90988 — Request a Quote &lt;= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum</title>
    <updated>2026-10-02T06:00:24.780000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown Request a Quote</p>
<p>The Request a Quote  WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-90988"/>
    <published>2026-10-02T06:00:24.780000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-85004</id>
    <title>CVE-2026-85004 — Popup Maker WP &lt;= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect</title>
    <updated>2026-10-02T06:00:24.239000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown Popup Maker</p>
<p>The Popup Maker  WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker  WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-85004"/>
    <published>2026-10-02T06:00:24.239000+00:00</published>
  </entry>
</feed>
