<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/nvd/10</id>
  <title>Most recent entries from nvd</title>
  <updated>2026-10-02T08:51:11.197810+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-97415</id>
    <title>CVE-2026-97415 — btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF</title>
    <updated>2026-10-02T06:28:24.434000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Linux</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF</p>
<p>ROOT_REF and ROOT_BACKREF items contain a struct btrfs_root_ref followed
by the subvolume name. Several readers assume that this layout is already
valid and then use the on-disk name length directly. A corrupted item can
therefore make those readers address bytes outside the item, and
BTRFS_IOC_GET_SUBVOL_INFO can copy too many bytes into its fixed-size UAPI
name buffer.</p>
<p>Validate ROOT_REF and ROOT_BACKREF items in tree-checker before any reader
uses them. Reject records that do not contain a non-empty name, whose
name_len does not exactly describe the remaining item payload, or whose
name exceeds BTRFS_NAME_LEN.</p>
<p>For BTRFS_IOC_GET_SUBVOL_INFO, copy only the validated on-disk name_len
instead of deriving the copy length from the item size. The ioctl result is
zeroed when allocated. That leaves the existing trailing zero byte
untouched.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-97415"/>
    <published>2026-09-24T16:03:22.780000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-97219</id>
    <title>CVE-2026-97219 — MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter</title>
    <updated>2026-10-02T06:56:54.228000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown MStore API</p>
<p>The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-97219"/>
    <published>2026-10-02T06:56:54.228000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-93698</id>
    <title>CVE-2026-93698</title>
    <updated>2026-10-02T06:20:33.663000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Webpros cPanel, Webpros WP Squared</p>
<p>Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-93698"/>
    <published>2026-10-02T06:20:33.663000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-93697</id>
    <title>CVE-2026-93697</title>
    <updated>2026-10-02T06:20:44.084000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Webpros cPanel, Webpros WP Squared</p>
<p>There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-93697"/>
    <published>2026-10-02T06:20:44.084000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-93029</id>
    <title>CVE-2026-93029</title>
    <updated>2026-10-02T06:20:47.333000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Webpros cPanel, Webpros WP Squared</p>
<p>There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-93029"/>
    <published>2026-10-02T06:20:47.333000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-92924</id>
    <title>CVE-2026-92924 — Unlimited Elements For Elementor &lt; 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data</title>
    <updated>2026-10-02T06:56:53.564000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown Unlimited Elements for Elementor</p>
<p>The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-92924"/>
    <published>2026-10-02T06:56:53.564000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-91020</id>
    <title>CVE-2026-91020 — WebToffee Gift Cards for WooCommerce &lt; 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount</title>
    <updated>2026-10-02T06:56:52.902000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown WebToffee Gift Cards for WooCommerce</p>
<p>The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-91020"/>
    <published>2026-10-02T06:56:52.902000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-90987</id>
    <title>CVE-2026-90987 — Easy PayPal &amp; Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price</title>
    <updated>2026-10-02T06:56:52.240000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown Easy PayPal &amp; Stripe Buy Now Button</p>
<p>The Easy PayPal &amp; Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-90987"/>
    <published>2026-10-02T06:56:52.240000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-90952</id>
    <title>CVE-2026-90952 — WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API</title>
    <updated>2026-10-02T06:56:51.595000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown WP Edit Password Protected</p>
<p>The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-90952"/>
    <published>2026-10-02T06:56:51.595000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-85005</id>
    <title>CVE-2026-85005 — Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization</title>
    <updated>2026-10-02T06:56:50.943000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Unknown Popup Maker WP</p>
<p>The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-85005"/>
    <published>2026-10-02T06:56:50.943000+00:00</published>
  </entry>
</feed>
