<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from cvelistv5</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:00:39 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-63569 — MTI/A0 DHAgreement does not validate the peer's ephemeral value</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-63569</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Legion of the Bouncy Castle Inc. bc-csharp&lt;/p&gt;
&lt;p&gt;Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the local party compute an agreed value the attacker already knows, defeating the key authentication MTI/A0 is meant to provide. It also allows a malicious peer to learn the local static private key modulo the small factors of p-1, and to recover it entirely in groups with many such factors. The attack uses a crafted out-of-range or small-order ephemeral value, and works because that value is raised to the static private key without the range and subgroup-membership checks applied to DH public keys. Only applications that call DHAgreement directly are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Legion of the Bouncy Castle Inc. bc-csharp&lt;/p&gt;
&lt;p&gt;Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the local party compute an agreed value the attacker already knows, defeating the key authentication MTI/A0 is meant to provide. It also allows a malicious peer to learn the local static private key modulo the small factors of p-1, and to recover it entirely in groups with many such factors. The attack uses a crafted out-of-range or small-order ephemeral value, and works because that value is raised to the static private key without the range and subgroup-membership checks applied to DH public keys. Only applications that call DHAgreement directly are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-63569</guid>
      <pubDate>Fri, 02 Oct 2026 07:00:23 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-63568 — Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-63568</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Legion of the Bouncy Castle Inc. bc-csharp&lt;/p&gt;
&lt;p&gt;Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a CMP message or CRMF certificate request whose PBMParameter declares a very large iteration count, because PKMacBuilder enforced its iteration-count ceiling only when the caller had supplied an explicit maximum through the PKMacBuilder(IPKMacPrimitivesProvider, int) constructor. With any other constructor, ProtectedPkiMessage.Verify and CertificateRequestMessage.IsValidSigningKeyPop performed as many hash iterations as the sender requested, up to about 2^31, before the MAC could be checked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Legion of the Bouncy Castle Inc. bc-csharp&lt;/p&gt;
&lt;p&gt;Allocation of resources without limits or throttling in the CMP/CRMF password-based MAC verifier (PKMacBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated attacker to cause a denial of service through CPU exhaustion via a CMP message or CRMF certificate request whose PBMParameter declares a very large iteration count, because PKMacBuilder enforced its iteration-count ceiling only when the caller had supplied an explicit maximum through the PKMacBuilder(IPKMacPrimitivesProvider, int) constructor. With any other constructor, ProtectedPkiMessage.Verify and CertificateRequestMessage.IsValidSigningKeyPop performed as many hash iterations as the sender requested, up to about 2^31, before the MAC could be checked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-63568</guid>
      <pubDate>Fri, 02 Oct 2026 06:59:30 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-63567 — IesEngine block-cipher mode checks padding before MAC (CBC padding oracle)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-63567</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Legion of the Bouncy Castle Inc. bc-csharp&lt;/p&gt;
&lt;p&gt;Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit modified ciphertexts for decryption under the same key pair, to recover its plaintext via a CBC padding-oracle attack, because in block-cipher mode the engine decrypts the ciphertext and removes its padding before verifying the MAC. A padding failure is therefore reported with a different error message, and without the MAC computation, compared with a MAC failure. Only applications that construct IesEngine directly with a padded block cipher, such as AES in CBC mode with PKCS#7 padding, are affected; stream-mode IES is not.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Legion of the Bouncy Castle Inc. bc-csharp&lt;/p&gt;
&lt;p&gt;Observable discrepancy in IesEngine.DecryptBlock in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker who has captured an IES or ECIES ciphertext, and who can submit modified ciphertexts for decryption under the same key pair, to recover its plaintext via a CBC padding-oracle attack, because in block-cipher mode the engine decrypts the ciphertext and removes its padding before verifying the MAC. A padding failure is therefore reported with a different error message, and without the MAC computation, compared with a MAC failure. Only applications that construct IesEngine directly with a padded block cipher, such as AES in CBC mode with PKCS#7 padding, are affected; stream-mode IES is not.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-63567</guid>
      <pubDate>Fri, 02 Oct 2026 06:58:32 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-63566 — DTLS handshake reassembler allocates buffer from unchecked 24-bit length</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-63566</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Legion of the Bouncy Castle Inc. bc-csharp&lt;/p&gt;
&lt;p&gt;Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated DTLS peer to cause a denial of service through memory exhaustion via crafted handshake message fragments, because the reassembly buffer for each incoming handshake message was allocated at the 24-bit length declared in the fragment header, without the check against the peer&amp;#39;s maximum handshake message size that TLS already applied. A fragment carrying no payload can force an allocation of almost 16 MB, for each of up to 16 pending messages per handshake, before the handshake is authenticated. DTLS servers and DTLS clients are both affected; TLS is not.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Legion of the Bouncy Castle Inc. bc-csharp&lt;/p&gt;
&lt;p&gt;Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReassembler) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote unauthenticated DTLS peer to cause a denial of service through memory exhaustion via crafted handshake message fragments, because the reassembly buffer for each incoming handshake message was allocated at the 24-bit length declared in the fragment header, without the check against the peer&amp;#39;s maximum handshake message size that TLS already applied. A fragment carrying no payload can force an allocation of almost 16 MB, for each of up to 16 pending messages per handshake, before the handshake is authenticated. DTLS servers and DTLS clients are both affected; TLS is not.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-63566</guid>
      <pubDate>Fri, 02 Oct 2026 06:57:21 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-97219 — MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-97219</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown MStore API&lt;/p&gt;
&lt;p&gt;The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown MStore API&lt;/p&gt;
&lt;p&gt;The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-97219</guid>
      <pubDate>Fri, 02 Oct 2026 06:56:54 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-92924 — Unlimited Elements For Elementor &lt; 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-92924</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Unlimited Elements for Elementor&lt;/p&gt;
&lt;p&gt;The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Unlimited Elements for Elementor&lt;/p&gt;
&lt;p&gt;The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-92924</guid>
      <pubDate>Fri, 02 Oct 2026 06:56:53 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-91020 — WebToffee Gift Cards for WooCommerce &lt; 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-91020</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown WebToffee Gift Cards for WooCommerce&lt;/p&gt;
&lt;p&gt;The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown WebToffee Gift Cards for WooCommerce&lt;/p&gt;
&lt;p&gt;The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-91020</guid>
      <pubDate>Fri, 02 Oct 2026 06:56:52 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-90987 — Easy PayPal &amp; Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-90987</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Easy PayPal &amp;amp; Stripe Buy Now Button&lt;/p&gt;
&lt;p&gt;The Easy PayPal &amp;amp; Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Easy PayPal &amp;amp; Stripe Buy Now Button&lt;/p&gt;
&lt;p&gt;The Easy PayPal &amp;amp; Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-90987</guid>
      <pubDate>Fri, 02 Oct 2026 06:56:52 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-90952 — WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-90952</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown WP Edit Password Protected&lt;/p&gt;
&lt;p&gt;The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site&amp;#39;s access mode was configured to hide.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown WP Edit Password Protected&lt;/p&gt;
&lt;p&gt;The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site&amp;#39;s access mode was configured to hide.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-90952</guid>
      <pubDate>Fri, 02 Oct 2026 06:56:51 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-85005 — Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-85005</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Popup Maker WP&lt;/p&gt;
&lt;p&gt;The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Popup Maker WP&lt;/p&gt;
&lt;p&gt;The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-85005</guid>
      <pubDate>Fri, 02 Oct 2026 06:56:50 +0000</pubDate>
    </item>
  </channel>
</rss>
