
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
2026-04-27
CVE-2026-6741: LatePoint <= 5.4.1 – Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability (latepoint)
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 5.4.1. This is due to a missing authorization check in the execute() method of the connect-customer-to-wp-user ability, which only requires the customer__edit capability granted to the latepoint_agent role by default, without…
2026-04-27
CVE-2026-6809: Social Post Embed <= 2.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Threads Embed (social-post-embed)
The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in all versions up to, and including, 2.0.1. This is due to insufficient input sanitization and output escaping on the user-supplied URL. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary…
2026-04-27
CVE-2026-6725: WPC Smart Messages for WooCommerce <= 4.2.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute (wpc-smart-messages)
The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcsm_text_rotator` shortcode in all versions up to, and including, 4.2.8. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access…
2026-04-27
CVE-2026-6551: Timeline Blocks for Gutenberg <= 1.1.10 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' Block Attribute (timeline-blocks)
The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to…
2026-04-27
CVE-2026-4911: Booking Package <= 1.7.06 – Unauthenticated Price Manipulation via 'amount' Parameter (booking-package)
The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amount'] directly to the Stripe PaymentIntent API without validation, and the commitStripe() function ignoring the server-calculated amount when confirming the payment. While the server correctly calculates the booking…
2026-04-26
CVE-2026-7106: Highland Software Custom Role Manager <= 1.0.0 – Authenticated (Subscriber+) Privilege Escalation (highland-software-custom-role-manager)
The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked to the personal_options_update action accessible by any authenticated user. This makes it possible for authenticated attackers, with Subscriber-level access or…
2026-04-22
CVE-2026-2951: Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML (gutentor)
The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that…
2026-04-22
CVE-2026-5464: ExactMetrics <= 9.1.2 – Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process (google-analytics-dashboard-for-wp)
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation in all versions up to, and including, 9.1.2. This is due to the reports page exposing the 'onboarding_key' transient to any user with the 'exactmetrics_view_dashboard' capability. This key is the sole authorization…
2026-04-22
CVE-2026-1923: Social Rocket – Social Sharing Plugin <= 1.3.4.2 – Authenticated (Subscriber+) Stored Cross-Site Scripting via id (social-rocket)
The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages…
2026-04-22
CVE-2026-3844: Breeze Cache <= 2.4.4 – Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote (breeze)
The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability…
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
