<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from nvd</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:51:05 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-97415 — btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-97415</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF&lt;/p&gt;
&lt;p&gt;ROOT_REF and ROOT_BACKREF items contain a struct btrfs_root_ref followed
by the subvolume name. Several readers assume that this layout is already
valid and then use the on-disk name length directly. A corrupted item can
therefore make those readers address bytes outside the item, and
BTRFS_IOC_GET_SUBVOL_INFO can copy too many bytes into its fixed-size UAPI
name buffer.&lt;/p&gt;
&lt;p&gt;Validate ROOT_REF and ROOT_BACKREF items in tree-checker before any reader
uses them. Reject records that do not contain a non-empty name, whose
name_len does not exactly describe the remaining item payload, or whose
name exceeds BTRFS_NAME_LEN.&lt;/p&gt;
&lt;p&gt;For BTRFS_IOC_GET_SUBVOL_INFO, copy only the validated on-disk name_len
instead of deriving the copy length from the item size. The ioctl result is
zeroed when allocated. That leaves the existing trailing zero byte
untouched.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF&lt;/p&gt;
&lt;p&gt;ROOT_REF and ROOT_BACKREF items contain a struct btrfs_root_ref followed
by the subvolume name. Several readers assume that this layout is already
valid and then use the on-disk name length directly. A corrupted item can
therefore make those readers address bytes outside the item, and
BTRFS_IOC_GET_SUBVOL_INFO can copy too many bytes into its fixed-size UAPI
name buffer.&lt;/p&gt;
&lt;p&gt;Validate ROOT_REF and ROOT_BACKREF items in tree-checker before any reader
uses them. Reject records that do not contain a non-empty name, whose
name_len does not exactly describe the remaining item payload, or whose
name exceeds BTRFS_NAME_LEN.&lt;/p&gt;
&lt;p&gt;For BTRFS_IOC_GET_SUBVOL_INFO, copy only the validated on-disk name_len
instead of deriving the copy length from the item size. The ioctl result is
zeroed when allocated. That leaves the existing trailing zero byte
untouched.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-97415</guid>
      <pubDate>Thu, 24 Sep 2026 16:03:22 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-97219 — MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-97219</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown MStore API&lt;/p&gt;
&lt;p&gt;The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown MStore API&lt;/p&gt;
&lt;p&gt;The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-97219</guid>
      <pubDate>Fri, 02 Oct 2026 06:56:54 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-93698</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-93698</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Webpros cPanel, Webpros WP Squared&lt;/p&gt;
&lt;p&gt;Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Webpros cPanel, Webpros WP Squared&lt;/p&gt;
&lt;p&gt;Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-93698</guid>
      <pubDate>Fri, 02 Oct 2026 06:20:33 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-93697</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-93697</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Webpros cPanel, Webpros WP Squared&lt;/p&gt;
&lt;p&gt;There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Webpros cPanel, Webpros WP Squared&lt;/p&gt;
&lt;p&gt;There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-93697</guid>
      <pubDate>Fri, 02 Oct 2026 06:20:44 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-93029</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-93029</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Webpros cPanel, Webpros WP Squared&lt;/p&gt;
&lt;p&gt;There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Webpros cPanel, Webpros WP Squared&lt;/p&gt;
&lt;p&gt;There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-93029</guid>
      <pubDate>Fri, 02 Oct 2026 06:20:47 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-92924 — Unlimited Elements For Elementor &lt; 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_data</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-92924</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Unlimited Elements for Elementor&lt;/p&gt;
&lt;p&gt;The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Unlimited Elements for Elementor&lt;/p&gt;
&lt;p&gt;The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level access, so from 2.0.18 onward the issue requires a Contributor role or above.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-92924</guid>
      <pubDate>Fri, 02 Oct 2026 06:56:53 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-91020 — WebToffee Gift Cards for WooCommerce &lt; 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amount</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-91020</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown WebToffee Gift Cards for WooCommerce&lt;/p&gt;
&lt;p&gt;The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown WebToffee Gift Cards for WooCommerce&lt;/p&gt;
&lt;p&gt;The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-91020</guid>
      <pubDate>Fri, 02 Oct 2026 06:56:52 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-90987 — Easy PayPal &amp; Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied Price</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-90987</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Easy PayPal &amp;amp; Stripe Buy Now Button&lt;/p&gt;
&lt;p&gt;The Easy PayPal &amp;amp; Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Easy PayPal &amp;amp; Stripe Buy Now Button&lt;/p&gt;
&lt;p&gt;The Easy PayPal &amp;amp; Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-90987</guid>
      <pubDate>Fri, 02 Oct 2026 06:56:52 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-90952 — WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-90952</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown WP Edit Password Protected&lt;/p&gt;
&lt;p&gt;The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site&amp;#39;s access mode was configured to hide.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown WP Edit Password Protected&lt;/p&gt;
&lt;p&gt;The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site&amp;#39;s access mode was configured to hide.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-90952</guid>
      <pubDate>Fri, 02 Oct 2026 06:56:51 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-85005 — Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-85005</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Popup Maker WP&lt;/p&gt;
&lt;p&gt;The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Unknown Popup Maker WP&lt;/p&gt;
&lt;p&gt;The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-85005</guid>
      <pubDate>Fri, 02 Oct 2026 06:56:50 +0000</pubDate>
    </item>
  </channel>
</rss>
