
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-24569: Media Library File Size <= 1.6.7 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24569 in Media Library File Size (CVSS 4.3): Media Library File Size. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.6.8.
March 18, 2026
CVE-2026-24567: Anything Order by Terms <= 1.4.0 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24567 in Anything Order By Terms (CVSS 4.3): Anything Order by Terms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-67968: Real Homes CRM <= 1.0.0 Authenticated (Subscriber+) Arbitrary File Upload PoC, Patch Analysis & Rule
High CVE-2025-67968 in Realhomes Crm (CVSS 8.8): Real Homes CRM. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-67958: TaxCloud for WooCommerce <= 8.3.8 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-67958 in Simple Sales Tax (CVSS 5.3): TaxCloud for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 8.4.0.
March 18, 2026
CVE-2025-68866: Dinatur <= 1.18 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2025-68866 in Dinatur (CVSS 7.2): Dinatur. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-67957: Listivo Core <= 2.3.77 Unauthenticated Local File Inclusion PoC, Patch Analysis & Rule
High CVE-2025-67957 in Listivo Core (CVSS 8.1): Listivo Core. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-0554: NotificationX <= 3.1.11 Missing Authorization to Authenticated (Contributor+) Analytics Reset PoC, Patch Analysis & Rule
Medium CVE-2026-0554 in Notificationx (CVSS 4.3): NotificationX. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.2.1.
March 18, 2026
CVE-2026-0690: FlatPM – Ad Manager, AdSense and Custom Code <= 3.2.2 Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Post Meta PoC, Patch Analysis & Rule
Medium CVE-2026-0690 in Flatpm Wp (CVSS 6.4): FlatPM – Ad Manager, AdSense and Custom Code. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.2.3.
March 18, 2026
CVE-2026-0608: Head Meta Data <= 20251118 Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta PoC, Patch Analysis & Rule
Medium CVE-2026-0608 in Head Meta Data (CVSS 6.4): Head Meta Data. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 20260105.
March 18, 2026
CVE-2025-15380: NotificationX <= 3.2.0 Unauthenticated DOM-Based Cross-Site Scripting via 'nx-preview' PoC, Patch Analysis & Rule
High CVE-2025-15380 in Notificationx (CVSS 7.2): NotificationX. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.2.1.
March 18, 2026
CVE-2026-24577: Pie Register <= 3.8.4.7 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24577 in Pie Register (CVSS 5.3): Pie Register. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.8.4.8.
March 18, 2026
CVE-2026-0726: Nexter Extension – Site Enhancements Toolkit <= 4.4.6 Unauthenticated PHP Object Injection via 'nxt_unserialize_replace' PoC, Patch Analysis & Rule
High CVE-2026-0726 in Nexter Extension (CVSS 8.1): Nexter Extension – Site Enhancements Toolkit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.4.7.
March 18, 2026
CVE-2026-0548: Tutor LMS – eLearning and online course solution <= 3.9.4 Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion PoC, Patch Analysis & Rule
Medium CVE-2026-0548 in Tutor (CVSS 5.4): Tutor LMS – eLearning and online course solution. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.9.5.
March 18, 2026
CVE-2025-15347: Creator LMS – The LMS for Creators, Coaches, and Trainers <= 1.1.12 Missing Authorization to Authenticated (Contributor+) Arbitrary Options Update PoC, Patch Analysis & Rule
High CVE-2025-15347 in Creatorlms (CVSS 8.8): Creator LMS – The LMS for Creators, Coaches, and Trainers. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.1.13.
March 18, 2026
CVE-2025-15043: The Events Calendar <= 6.15.13 Missing Authorization to Authenticated (Subscriber+) Data Migration Control PoC, Patch Analysis & Rule
Medium CVE-2025-15043 in The Events Calendar (CVSS 5.4): The Events Calendar. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 6.15.13.1.
March 18, 2026
CVE-2026-24575: WishList Member X <= 3.29.0 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24575 in Wishlist Member X (CVSS 4.3): WishList Member X. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-68020: WANotifier <= 2.7.12 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-68020 in Notifier (CVSS 5.3): WANotifier. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.7.13.
March 18, 2026
CVE-2025-68046: Contact Form & Lead Form Elementor Builder <= 2.0.1 Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2025-68046 in Lead Form Builder (CVSS 4.3): Contact Form & Lead Form Elementor Builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.0.3.
March 18, 2026
CVE-2025-69315: Simply Schedule Appointments <= 1.6.9.15 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-69315 in Simply Schedule Appointments (CVSS 5.3): Simply Schedule Appointments. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.6.9.17.
March 18, 2026
CVE-2026-24579: Ai Image Alt Text Generator for WP <= 1.1.9 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24579 in Ai Image Alt Text Generator For Wp (CVSS 4.3): Ai Image Alt Text Generator for WP. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
