Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

July 26, 2026

CVE-2025-66076: Woostify Sites Library <= 1.6.2 Missing Authorization PoC, Patch Analysis & Rule

CVE-2025-66076 affects the Woostify Sites Library plugin for WordPress (up to v1.6.2) with a medium severity (CVSS 5.3) vulnerability due to missing authorization checks. Update to the latest version to mitigate unauthorized access risks.
July 26, 2026

CVE-2026-57625: Admin and Site Enhancements (ASE) Pro <= 8.8.5 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-57625 affects the Admin Site Enhancements Pro plugin for WordPress (up to v8.8.5) with a CVSS score of 7.2. Unauthenticated attackers can exploit this XSS vulnerability; patching is essential to mitigate risks.
July 26, 2026

CVE-2025-69134: OpenAI Chatbot for WordPress – Helper <= 1.1.4 Missing Authorization to Unauthenticated Arbitrary Content Deletion PoC, Patch Analysis & Rule

CVE-2025-69134 affects the Helper plugin for WordPress (up to 1.1.4) with a medium severity CVSS score of 5.3. Unauthenticated attackers can delete content due to a missing capability check. Patching is essential.
July 26, 2026

CVE-2026-57688: POS Entegratör – Gurmehub Ödeme Eklentisi <= 3.7.103 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-57688 affects the POS Entegratör plugin for WordPress (up to version 3.7.103) with a medium severity score of 5.3. Users should upgrade to version 3.8.0 to mitigate unauthorized access risks.
July 26, 2026

CVE-2026-57331: Paid Videochat Turnkey Site – HTML5 PPV Live Webcams <= 7.4.8 Authenticated (Performer+) Arbitrary File Deletion PoC, Patch Analysis & Rule

CVE-2026-57331 affects the Ppv Live Webcams plugin (up to version 7.4.8) with a high severity CVSS score of 8.1. Authenticated attackers can delete arbitrary files, risking remote code execution. Patch immediately.
July 26, 2026

CVE-2026-49779: Tax Exempt for WooCommerce <= 1.9.3 Authenticated (Customer+) Path Traversal PoC, Patch Analysis & Rule

CVE-2026-49779 affects the WooCommerce Tax Exempt Plugin (up to v1.9.3) with a medium severity CVSS score of 4.3. Authenticated attackers can exploit this path traversal vulnerability, so ensure timely patching.
July 26, 2026

CVE-2026-57677: Novalnet Payment Gateway for WooCommerce <= 12.10.3 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

CVE-2026-57677 reveals a high-severity PHP Object Injection vulnerability in the Novalnet Payment Gateway for WooCommerce (up to 12.10.3). Unauthenticated attackers may exploit this flaw, so patching is essential.
July 26, 2026

CVE-2026-56068: JetEngine <= 3.8.10.2 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2026-56068 affects the Jet Engine plugin for WordPress (up to version 3.8.10.2) with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated attackers to extract sensitive data. Patching is essential.
July 26, 2026

CVE-2026-57756: nicen-localize-image <= 1.4.9 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule

CVE-2026-57756 affects the Nicen Localize Image plugin for WordPress (up to 1.4.9) with a medium severity SQL injection vulnerability (CVSS 6.5). Update to the patched version to mitigate risks of data exposure.
July 26, 2026

CVE-2026-57429: Slim SEO – A Fast & Automated SEO Plugin For WordPress <= 4.6.2 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-57429 affects Slim SEO plugin versions up to 4.6.2, allowing authenticated attackers to perform unauthorized actions. Update to version 4.7.0 to mitigate this medium severity vulnerability.
July 26, 2026

CVE-2026-56045: WordPress Automatic Plugin < 3.135.1 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-56045 affects the WordPress Automatic Plugin (up to version 3.135.1) with a high severity CVSS score of 7.2. Unauthenticated stored XSS can lead to script injection; patching is essential to mitigate risks.
July 26, 2026

CVE-2026-56064: Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin <= 2.22.5 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule

CVE-2026-56064 affects the Tourfic plugin (up to version 2.22.5) with a medium severity SQL injection vulnerability (CVSS 6.5). Users should update to version 2.22.6 to mitigate risks of data exposure.
July 26, 2026

CVE-2026-56060: Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

CVE-2026-56060 affects the Print Invoice & Delivery Notes for WooCommerce plugin (up to v7.1.1) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability to access sensitive data. Update to v7.1.2.
July 26, 2026

CVE-2026-56049: Post Snippets – Custom WordPress Code Snippets Customizer <= 4.0.19 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule

CVE-2026-56049 affects the Post Snippets plugin (up to version 4.0.19) with a CVSS score of 8.8, allowing remote code execution for authenticated users. Upgrade to version 4.1.0 to mitigate this high-severity risk.
July 26, 2026

CVE-2026-57312: Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.4.8 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-57312 affects the Everest Forms plugin for WordPress (up to version 3.4.8) with a medium severity score of 6.1. Users should upgrade to version 3.5.0 to mitigate the reflected XSS vulnerability.
July 26, 2026

CVE-2026-57319: FOX – Currency Switcher Professional for WooCommerce <= 1.4.8 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-57319 affects the Woocommerce Currency Switcher plugin (up to version 1.4.8) with a CVSS score of 7.2. Unauthenticated attackers can exploit this XSS vulnerability, so update to version 1.4.9 to mitigate risks.
July 26, 2026

CVE-2026-57619: Elementor Website Builder – more than just a page builder <= 4.1.3 Authenticated (Contributor+) Sensitive Information Exposure PoC, Patch Analysis & Rule

CVE-2026-57619 affects Elementor versions up to 4.1.3, exposing sensitive data to authenticated attackers with Contributor access. Upgrade to 4.1.4 to mitigate this medium severity vulnerability with a CVSS score of 4.3.
July 26, 2026

CVE-2026-56066: ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.11.4 Unauthenticated Arbitrary File Deletion PoC, Patch Analysis & Rule

CVE-2026-56066 affects the ShortPixel Adaptive Images plugin (up to v3.11.4) with a CVSS score of 5.3. Unauthenticated attackers can delete arbitrary files, risking remote code execution. Upgrade to v3.11.5 to mitigate this risk.
July 26, 2026

CVE-2026-56063: Block for Mailchimp – Add Email Subscription Forms and Collect Leads <= 1.1.15 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-56063 affects the Block for Mailchimp plugin (up to v1.1.15) with a CVSS score of 5.3. It allows unauthorized access; update to v1.1.16 to mitigate this risk.
July 26, 2026

CVE-2026-56054: JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.1 Authenticated (Subscriber+) Arbitrary File Deletion PoC, Patch Analysis & Rule

CVE-2026-56054 affects the Js Support Ticket plugin for WordPress, allowing authenticated attackers to delete arbitrary files. This high severity vulnerability (CVSS 8.8) is patched in version 3.1.2; update immediately to mitigate risks.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works