
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
September 14, 2026
CVE-2025-8878: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.4 Unauthenticated Arbitrary Shortcode Execution PoC, Patch Analysis & Rule
CVE-2025-8878 affects the Wp User Avatar plugin (up to version 4.16.4), allowing unauthenticated remote code execution. Update to version 4.16.5 to mitigate this medium severity vulnerability.
August 28, 2026
CVE-2022-44587: WP 2FA <= 2.6.3 Unauthenticated Information Exposure via Log File PoC, Patch Analysis & Rule
CVE-2022-44587 affects the WP 2FA plugin (up to v2.6.3) with a medium severity (CVSS 5.3). Unauthenticated attackers can access sensitive data in exposed log files. Upgrade to v2.6.4 to mitigate this risk.
August 28, 2026
CVE-2025-48166: Stop and Block bots plugin Anti bots <= 1.48 Missing Authorization PoC, Patch Analysis & Rule
CVE-2025-48166 affects the Antibots plugin for WordPress (up to version 1.48) with a medium severity (CVSS 5.3). Unauthenticated attackers can exploit this vulnerability, making prompt patching essential.
August 18, 2026
CVE-2026-65498: Complianz – GDPR/CCPA Cookie Consent <= 7.5.1 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
CVE-2026-65498 affects the Complianz GDPR plugin (up to v7.5.1) with a medium severity (CVSS 5.3) vulnerability allowing data exposure. Update to v7.5.2 to mitigate the risk of sensitive information extraction.
August 16, 2026
CVE-2026-15345: ShortPixel Adaptive Images <= 3.11.5 Missing Authorization to Authenticated (Subscriber+) Third-Party Plugin Option Modification via 'causer' Parameter PoC, Patch Analysis & Rule
CVE-2026-15345 affects ShortPixel Adaptive Images versions up to 3.11.5, allowing authenticated users to bypass authorization. Upgrade to 3.11.6 to mitigate this medium severity vulnerability.
August 16, 2026
CVE-2026-15726: Serious Slider <= 1.4.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'theme' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-15726 affects the Serious Slider plugin for WordPress (up to 1.4.0) with a medium severity CVSS score of 6.4. Update to version 1.4.1 to mitigate Stored XSS risks from insufficient input sanitization.
August 16, 2026
CVE-2026-16098: ProSolution WP Client <= 2.0.10 Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override PoC, Patch Analysis & Rule
CVE-2026-16098 affects Prosolution WP Client versions up to 2.0.10, posing a critical risk with a CVSS score of 9.8. Update to version 2.0.11 to mitigate the arbitrary file upload vulnerability.
August 16, 2026
CVE-2026-14498: Query Wrangler <= 1.5.57 Authenticated (Subscriber+) Remote Code Execution via 'options' Parameter PoC, Patch Analysis & Rule
CVE-2026-14498 affects the Query Wrangler plugin for WordPress, with a high severity CVSS score of 8.8. Users should upgrade to version 1.5.58 to mitigate the risk of Remote Code Execution by authenticated attackers.
August 16, 2026
CVE-2026-15963: Quiz and Survey Master (QSM) <= 11.2.1 Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option PoC, Patch Analysis & Rule
CVE-2026-15963 affects the Quiz Master Next plugin (up to version 11.2.1) with a medium severity SQL injection vulnerability (CVSS 6.5). Update to version 11.2.2 to mitigate risks of data exposure.
August 16, 2026
CVE-2026-17123: Royal Addons for Elementor <= 1.7.1064 Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting PoC, Patch Analysis & Rule
CVE-2026-17123 affects the Royal Elementor Addons plugin (up to v1.7.1064) with a CVSS score of 8.8. Authenticated users can exploit this high-severity SSRF vulnerability. Update to v1.7.1065 to mitigate risks.
August 16, 2026
CVE-2026-14524: ProSolution WP Client <= 2.0.8 Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters PoC, Patch Analysis & Rule
CVE-2026-14524 affects the ProSolution WP Client plugin (versions up to 2.0.8) with a critical CVSS score of 9.1. Patch to version 2.0.9 to mitigate the risk of unauthenticated file deletion and potential remote code execution.
August 16, 2026
CVE-2026-15441: Product Table & List Builder For WooCommerce <= 5.6.0 Unauthenticated CSS Injection via 'laptop_scroll_offset' Parameter PoC, Patch Analysis & Rule
The WC Product Table Lite plugin for WordPress, versions up to 5.6.0, has a medium severity CSS Injection vulnerability (CVE-2026-15441) allowing unauthenticated attackers to inject CSS. Update to version 5.6.5 to mitigate risks.
August 16, 2026
CVE-2026-15066: Loco Translate <= 2.8.7 Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments PoC, Patch Analysis & Rule
CVE-2026-15066 affects Loco Translate versions up to 2.8.7, exposing users to a medium severity XSS vulnerability. Update to version 2.8.8 to mitigate risks from authenticated attackers injecting scripts.
August 16, 2026
CVE-2026-16099: Podlove Podcast Publisher <= 4.5.3 Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter PoC, Patch Analysis & Rule
CVE-2026-16099 affects the Podlove Podcasting Plugin for WordPress (up to v4.5.3) with a CVSS score of 8.8. Authenticated users can delete arbitrary files, potentially leading to remote code execution. Update to v4.5.4 to mitigate.
August 16, 2026
CVE-2026-12477: Gravity Booster <= 5.26 Authenticated (Editor+) Stored Cross-Site Scripting via 'stylerSettings' Parameter PoC, Patch Analysis & Rule
CVE-2026-12477 affects the Styles And Layouts For Gravity Forms plugin for WordPress (up to version 5.26) with a medium severity (CVSS 4.4) Stored XSS vulnerability. Update to version 6.0 to mitigate risks from authenticated attackers.
August 16, 2026
CVE-2026-15602: NEX-Forms <= 9.2.4 Authenticated (Admin+) SQL Injection via 'additional_params' Parameter PoC, Patch Analysis & Rule
CVE-2026-15602 affects the Nex Forms Express WP Form Builder plugin (up to v9.2.4) with a medium severity SQL injection vulnerability (CVSS 4.9). Update to v9.2.5 to mitigate risks from authenticated attackers.
August 16, 2026
CVE-2025-10005: Password Protect WordPress Lite <= 1.9.20 Insecure Direct Object Reference to Authenticated (Contributor+) Password Protected Post Password Update PoC, Patch Analysis & Rule
CVE-2025-10005 affects the Password Protect Page plugin (up to v1.9.20) with a medium severity (CVSS 4.3) IDOR vulnerability. Authenticated attackers can change passwords on protected posts. Update to v1.9.21 to mitigate this risk.
August 16, 2026
CVE-2026-18385: Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.19 Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field PoC, Patch Analysis & Rule
CVE-2026-18385 affects the ProfilePress plugin (up to v4.16.19), allowing authenticated users to execute arbitrary shortcodes. Upgrade to v4.17.0 to mitigate this medium-severity remote code execution risk.
August 16, 2026
CVE-2026-16779: Kubio AI Page Builder <= 2.8.5 Missing Authorization to Authenticated (Contributor+) Front-Page/Menu/Template Configuration Reversion via kubio_restore_front_page AJAX Action PoC, Patch Analysis & Rule
CVE-2026-16779 affects the Kubio AI Page Builder plugin (up to v2.8.5) with a medium severity (CVSS 4.3) authentication bypass. Users should upgrade to v2.8.6 to mitigate risks of unauthorized configuration changes.
August 16, 2026
CVE-2026-18432: Frontend Admin by DynamiApps <= 3.29.9 Unauthenticated Privilege Escalation via 'item_id' Parameter PoC, Patch Analysis & Rule
CVE-2026-18432 affects the Acf Frontend Form Element plugin (up to v3.29.9) with a critical CVSS score of 9.8. Patch to v3.29.10 to mitigate unauthenticated privilege escalation risks.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
