Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

July 2, 2026

CVE-2026-12731: weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes PoC, Patch Analysis & Rule

CVE-2026-12731 affects the weDocs plugin for WordPress (up to version 2.3.0) with a medium severity CVSS score of 6.4. Update to version 2.3.1 to mitigate stored XSS risks from authenticated attackers.
July 1, 2026

CVE-2026-9145: Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value' PoC, Patch Analysis & Rule

CVE-2026-9145 affects the Contact Form Entries plugin (up to v1.5.1) with a medium severity (CVSS 6.5) file upload vulnerability. Upgrade to v1.5.2 to mitigate risks of unauthorized file disclosure.
July 1, 2026

CVE-2026-13251: Perfmatters <= 2.6.4 Unauthenticated Arbitrary File Read via 's' Parameter PoC, Patch Analysis & Rule

CVE-2026-13251 affects the Perfmatters plugin for WordPress (up to version 2.6.4) with a CVSS score of 7.5. Unauthenticated attackers can exploit this file upload vulnerability to access sensitive server files. Patching is essential.
July 1, 2026

CVE-2026-13369: Ninja Forms File Uploads <= 3.3.29 Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter PoC, Patch Analysis & Rule

CVE-2026-13369 affects Ninja Forms Uploads plugin versions up to 3.3.29, allowing unauthenticated attackers to read arbitrary files. Update to the patched version to mitigate this high-severity vulnerability.
July 1, 2026

CVE-2026-8441: WP Review Slider Pro <= 12.7.2 Unauthenticated SQL Injection via 'notinstring' Parameter PoC, Patch Analysis & Rule

CVE-2026-8441 affects WP Review Slider Pro versions up to 12.7.2 with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated attackers to extract data. Patching is essential.
July 1, 2026

CVE-2026-13252: RSS Aggregator by Feedzy <= 5.2.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute PoC, Patch Analysis & Rule

CVE-2026-13252 affects the Feedzy Rss Feeds plugin (up to v5.2.1) with a CVSS score of 6.4. This medium-severity Stored XSS vulnerability allows authenticated users to inject scripts. Update to v5.2.2 to mitigate risks.
July 1, 2026

CVE-2026-10104: Product Video Gallery for Woocommerce <= 1.5.1.8 Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter PoC, Patch Analysis & Rule

CVE-2026-10104 affects the Product Video Gallery Slider for WooCommerce plugin (v1.5.1.8) with a medium severity (CVSS 4.4) XSS vulnerability. Update to v1.5.1.9 to mitigate risks from authenticated attacks.
July 1, 2026

CVE-2026-9188: Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 Unauthenticated Insecure Direct Object Reference via Predictable 'edit_key' / 'appointmentkey' Parameter PoC, Patch Analysis & Rule

CVE-2026-9188 affects the Wappointment plugin for WordPress (up to 2.7.6) with a CVSS score of 5.3. Unauthenticated users can exploit predictable keys to cancel or reschedule appointments. Update to version 2.7.7 to mitigate.
July 1, 2026

CVE-2026-12122: Kirki <= 6.0.11 Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action PoC, Patch Analysis & Rule

CVE-2026-12122 affects the Kirki plugin (up to version 6.0.11) with a medium severity (CVSS 5.3) vulnerability allowing unauthenticated access to sensitive data. Upgrade to version 6.0.12 to mitigate this risk.
July 1, 2026

CVE-2026-12657: LatePoint <= 5.6.2 Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter PoC, Patch Analysis & Rule

CVE-2026-12657 affects LatePoint plugin versions up to 5.6.2, allowing unauthenticated users to create unauthorized bookings. Update to version 5.6.3 to mitigate this medium severity vulnerability.
July 1, 2026

CVE-2026-13459: JetFormBuilder <= 3.6.3 Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter PoC, Patch Analysis & Rule

CVE-2026-13459 affects JetFormBuilder plugin versions up to 3.6.3, allowing unauthenticated access to sensitive WooCommerce PII due to an authentication bypass. Update to version 3.6.3.1 to mitigate this medium severity issue.
July 1, 2026

CVE-2026-11896: My Calendar <= 3.7.14 Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter PoC, Patch Analysis & Rule

CVE-2026-11896 affects the My Calendar plugin for WordPress (up to version 3.7.14) with a CVSS score of 5.3. Unauthenticated attackers can access sensitive event data; update to version 3.7.15 to mitigate this risk.
July 1, 2026

CVE-2026-14029: Groundhogg <= 4.5.8 Authenticated (Custom+) SQL Injection via 'select' Parameter PoC, Patch Analysis & Rule

CVE-2026-14029 affects Groundhogg plugin versions up to 4.5.8, allowing SQL injection by authenticated users with custom roles. Update to version 4.5.9 to mitigate this medium severity vulnerability.
July 1, 2026

CVE-2026-12134: JoomSport <= 5.7.8 Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action PoC, Patch Analysis & Rule

CVE-2026-12134 affects the Joomsport Sports League Results Management plugin (up to v5.7.8) with a medium severity (CVSS 4.3) authentication bypass. Patch to v5.7.9 to prevent unauthorized modifications by attackers.
July 1, 2026

CVE-2026-12472: Kirki <= 6.0.11 Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters PoC, Patch Analysis & Rule

CVE-2026-12472 affects the Kirki plugin (up to v6.0.11) with a medium severity (CVSS 5.3) authentication bypass. Update to v6.0.12 to mitigate risks of unauthorized email injection attacks.
July 1, 2026

CVE-2026-10089: Insert Pages <= 3.11.4 Authenticated (Author+) Stored Cross-Site Scripting via Custom Field Keys (Meta Key Names) PoC, Patch Analysis & Rule

CVE-2026-10089 affects the Insert Pages plugin for WordPress (up to version 3.11.4) with a medium severity XSS vulnerability. Update to version 3.11.5 to mitigate risks from authenticated attackers injecting scripts.
July 1, 2026

CVE-2026-11592: Email Subscribers & Newsletters <= 5.9.27 Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action PoC, Patch Analysis & Rule

CVE-2026-11592 affects the Email Subscribers plugin (up to version 5.9.27) with a CVSS score of 4.3. Authenticated attackers can exploit this medium-severity vulnerability to manipulate mail settings. Upgrade to 5.9.28 to mitigate risks.
July 1, 2026

CVE-2026-5821: Image Optimizer <= 1.7.4 Authenticated (Author+) Arbitrary File Deletion via Post Meta Field Injection PoC, Patch Analysis & Rule

CVE-2026-5821 affects the Image Optimization plugin (up to v1.7.4) with a CVSS score of 8.1. Authenticated attackers can exploit a file upload vulnerability to delete arbitrary files. Upgrade to v1.7.5 to mitigate this risk.
July 1, 2026

CVE-2026-13357: Houzez Property Feed <= 2.5.46 Authenticated (Administrator+) SQL Injection via 'orderby' Parameter PoC, Patch Analysis & Rule

CVE-2026-13357 affects the Houzez Property Feed plugin (up to version 2.5.46) with a medium severity SQL injection vulnerability (CVSS 4.9). Users should update to version 2.5.47 to mitigate risks associated with this flaw.
July 1, 2026

CVE-2026-13704: GiveWP <= 4.16.1 Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form PoC, Patch Analysis & Rule

CVE-2026-13704 affects the GiveWP plugin (up to version 4.16.1) with a medium severity CVSS score of 6.4. Patch to version 4.16.2 to mitigate Stored XSS risks from authenticated attackers injecting scripts.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works