<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/github/10</id>
  <title>Most recent entries from github</title>
  <updated>2026-10-02T07:58:02.762753+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vc58-2rcj-cgf8</id>
    <title>GHSA-vc58-2rcj-cgf8</title>
    <updated>2026-10-02T06:30:56+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Exploitation requires sending a malicious widgetData payload containing a legacy top-level theme key alongside a non-empty columns array to the /wp-json/sowb/v1/widgets/previews REST endpoint, which bypasses field validation because update_fields() only processes declared form fields.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vc58-2rcj-cgf8"/>
    <published>2026-10-02T06:30:56+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9949-jq7q-8g48</id>
    <title>GHSA-9949-jq7q-8g48</title>
    <updated>2026-10-02T06:30:56+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9949-jq7q-8g48"/>
    <published>2026-10-02T06:30:56+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-82gv-pr29-8vm2</id>
    <title>GHSA-82gv-pr29-8vm2</title>
    <updated>2026-10-02T06:30:56+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-82gv-pr29-8vm2"/>
    <published>2026-10-02T06:30:56+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7cq6-x444-93vj</id>
    <title>GHSA-7cq6-x444-93vj</title>
    <updated>2026-10-02T06:30:56+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the targeted Paragraph Text field has the Rich Text Editor (RTE) option enabled.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7cq6-x444-93vj"/>
    <published>2026-10-02T06:30:55+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-564m-jf3j-p556</id>
    <title>GHSA-564m-jf3j-p556</title>
    <updated>2026-10-02T06:30:56+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The BuildKit  WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated visitor.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-564m-jf3j-p556"/>
    <published>2026-10-02T06:30:56+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3v9p-5xxf-6hxg</id>
    <title>GHSA-3v9p-5xxf-6hxg</title>
    <updated>2026-10-02T06:30:56+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used without validation to attach a file to the form's notification email (arbitrary file read), to write fetched content (arbitrary file write, leading to remote code execution when the external store is configured), and in a scheduled deletion (arbitrary file deletion). This makes it possible for unauthenticated attackers to read, write, or delete arbitrary files on the server. Exploitation requires the site to use the plugin's External File Upload (Amazon S3) action; the read variant additionally requires a form Email action configured to attach the uploaded file.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3v9p-5xxf-6hxg"/>
    <published>2026-10-02T06:30:56+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-whfp-wchg-v9xw</id>
    <title>GHSA-whfp-wchg-v9xw</title>
    <updated>2026-10-02T06:30:55+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Motors  WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors  WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-whfp-wchg-v9xw"/>
    <published>2026-10-02T06:30:55+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r39q-9952-j46j</id>
    <title>GHSA-r39q-9952-j46j</title>
    <updated>2026-10-02T06:30:55+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Super Forms – Drag &amp; Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r39q-9952-j46j"/>
    <published>2026-10-02T06:30:55+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h8h9-7p7r-7rpq</id>
    <title>GHSA-h8h9-7p7r-7rpq</title>
    <updated>2026-10-02T06:30:55+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Super Forms – Drag &amp; Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register &amp; Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action='update' with register_login_user_id_update='true') and then submit it with user_id set to an administrator's ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts — including administrators — resulting in account takeover and full site compromise.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h8h9-7p7r-7rpq"/>
    <published>2026-10-02T06:30:55+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h25v-5897-j3vf</id>
    <title>GHSA-h25v-5897-j3vf</title>
    <updated>2026-10-02T06:30:55+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Motors  WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h25v-5897-j3vf"/>
    <published>2026-10-02T06:30:55+00:00</published>
  </entry>
</feed>
