Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

2026-05-19

CVE-2026-6549: Logo Manager For Enamad <= 0.7.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute (logo-manager-for-enamad)

The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes in all versions up to, and including, 0.7.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access…
2026-05-19

CVE-2026-8624: LJ comments import: reloaded <= 0.97.1 – Reflected Cross-Site Scripting via PHP_SELF Parameter (lj-comments-import-reloaded)

The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a…
2026-05-19

CVE-2026-8626: SponsorMe <= 0.5.2 – Reflected Cross-Site Scripting via PHP_SELF Parameter (sponsorme)

The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing…
2026-05-19

CVE-2026-6728: Slider Revolution <= 7.0.9 – Unauthenticated Sensitive Information Exposure via 'sliders/stream' (revslider)

The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes it possible for unauthenticated attackers to extract sensitive data including published password-protected post, page, and product content.
2026-05-19

CVE-2026-7472: Read More & Accordion <= 3.5.7 – Authenticated (Administrator+) SQL Injection via 'orderby' Parameter (expand-maker)

The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.5.7. This is due to the use of esc_sql() without surrounding the value in quotes in an ORDER BY clause inside the getAllDataByLimit() and getAccordionAllDataByLimit() functions in ReadMoreData.php. The…
2026-05-19

CVE-2026-8627: Correct Prices <= 1.0 – Reflected Cross-Site Scripting via PHP_SELF Parameter (correct-prices)

The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to and including 1.0. This is due to the correct_prices_page() function echoing $_SERVER['PHP_SELF'] into a form's action attribute without any input sanitization or output escaping (such as esc_url() or esc_attr()). Because PHP_SELF reflects attacker-controlled path-info appended…
2026-05-19

CVE-2026-7467: Read More & Accordion <= 3.5.7 – Privilege Escalation via importData (expand-maker)

The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting which database tables can be written to during import and not properly validating the imported data. This makes it possible for authenticated attackers, with permission…
2026-05-19

CVE-2026-8610: TypeSquare Webfonts for ConoHa <= 2.0.4 – Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification via 'fontThemeUseType' Parameter (ts-webfonts-for-conoha)

The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the plugin's…
2026-05-19

CVE-2026-6405: Anomify AI <= 0.3.6 – Cross-Site Request Forgery (anomify)

The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in versions up to and including 0.3.6. This is due to missing nonce verification on the settings page handler and insufficient output escaping in the admin_options.php template. The settings form includes…
2026-05-19

CVE-2026-7284: Easy Elements for Elementor <= 1.4.4 – Unauthenticated Privilege Escalation via easyel_handle_register (easy-elements)

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply…
2026-05-19

CVE-2026-3985: Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 – Unauthenticated SQL Injection via 'checkout_uuid' Parameter (creative-mail-by-constant-contact)

The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the `has_checkout_consent()` method.…
2026-05-19

CVE-2026-9010: Boost <= 2.0.3 – Unauthenticated Blind SQL Injection via Multiple Parameters (boost)

The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL queries. This makes it possible for unauthenticated attackers to append additional SQL queries…
2026-05-19

CVE-2025-15369: Xpro Addons — 140+ Widgets for Elementor <= 1.5.0 – Missing Authorization to Unauthenticated Xpro Template Creation (xpro-elementor-addons)

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the get_content_editor function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to create published Xpro templates.
2026-05-19

CVE-2026-2955: AI Chatbot & Workflow Automation by AIWU <= 1.4.14 – Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' Header (ai-copilot-content-generator)

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in versions up to, and including, 1.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a…
2026-05-19

CVE-2026-5200: AcyMailing <= 10.8.2 – Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via 'acymailing_router' (acymailing)

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level…
2026-05-19

CVE-2026-5075: All in One SEO <= 4.9.7 – Authenticated (Contributor+) Sensitive Information Exposure via 'internalOptions' Localized Script Data (all-in-one-seo-pack)

The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized script data in versions up to, and including, 4.9.7 due to sensitive internal option data being passed to wp_localize_script() in post editor contexts without effective masking for low-privilege users. This makes it possible for authenticated attackers, with contributor-level…
2026-05-19

CVE-2026-6566: Photo Gallery, Sliders, Proofing and Themes <= 4.2.0 – Insecure Direct Object Reference to Authenticated (Subscriber+) Image Deletion via REST API (nextgen-gallery)

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 4.2.0. This is due to insufficient object-level authorization in the image deletion REST flow where the permission callback for DELETE /imagely/v1/images/{id} only checks 'NextGEN Manage gallery' permissions and does…
2026-05-19

CVE-2026-7522: Advanced Database Cleaner – Premium <= 4.1.0 – Authenticated (Subscriber+) Local File Inclusion via 'template' (advanced-database-cleaner-premium)

The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 'template' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code…
2026-05-19

CVE-2026-7613: Cost of Goods by PixelYourSite <= 1.2.12 – Unauthenticated Stored Cross-Site Scripting via Cost of Goods Import (pixel-cost-of-goods)

The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses…
2026-05-19

CVE-2026-7637: Boost <= 2.0.3 – Unauthenticated PHP Object Injection via STYXKEY-BOOST_USER_LOCATION Cookie (boost)

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no…

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works