
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
July 1, 2026
CVE-2026-14249: Request a Quote Form Plugin <= 2.5.5 Unauthenticated Code Injection via 'path' Parameter PoC, Patch Analysis & Rule
CVE-2026-14249 affects the Request A Quote plugin for WordPress (up to version 2.5.5) with a CVSS score of 7.5. Unauthenticated code injection is possible; update to version 2.5.6 to mitigate this high-severity vulnerability.
July 1, 2026
CVE-2026-32488: User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 4.4.9 Unauthenticated Remote Code Execution PoC, Patch Analysis & Rule
CVE-2026-32488 affects the User Registration plugin for WordPress, allowing remote code execution in versions up to 4.4.9. With a CVSS score of 9.8, users should upgrade to version 5.1.3 to mitigate this critical vulnerability.
June 30, 2026
CVE-2026-10095: WP Photo Album Plus <= 9.1.13.005 Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-10095 affects the WP Photo Album Plus plugin (up to 9.1.13.005) with a CVSS score of 6.4. Authenticated users can exploit stored XSS via the 'subtext' parameter. Update to version 9.2.01.001 to mitigate this risk.
June 30, 2026
CVE-2026-13228: LatePoint <= 5.6.3 Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter PoC, Patch Analysis & Rule
CVE-2026-13228 affects the LatePoint plugin (up to version 5.6.3) with a CVSS score of 8.8. Authenticated attackers can escalate privileges to Administrator. Update to version 5.6.4 to mitigate this vulnerability.
June 30, 2026
CVE-2026-12142: NEX-Forms <= 9.2.2 Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter PoC, Patch Analysis & Rule
CVE-2026-12142 affects the Nex Forms Express WP Form Builder plugin (up to 9.2.2) with a high severity CVSS score of 7.2. Unauthenticated XSS vulnerabilities can be mitigated by updating to version 9.2.3.
June 30, 2026
CVE-2026-12754: VikBooking Hotel Booking Engine & PMS <= 1.8.12 Reflected Cross-Site Scripting via 'layoutstyle' Parameter PoC, Patch Analysis & Rule
CVE-2026-12754 affects the Vikbooking plugin (up to 1.8.12) with a CVSS score of 6.1. This medium severity XSS vulnerability allows unauthenticated attackers to inject scripts. Update to 1.8.13 to mitigate risks.
June 30, 2026
CVE-2026-13454: MotoPress Appointment Booking <= 2.4.5 Authenticated (Staff+) SQL Injection via 's' Parameter PoC, Patch Analysis & Rule
CVE-2026-13454 affects the Motopress Appointment Lite plugin (up to v2.4.5) with a medium severity SQL injection vulnerability. Users should upgrade to v2.4.6 to mitigate potential data exposure risks.
June 30, 2026
CVE-2026-12408: Slim SEO <= 4.9.8 Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter PoC, Patch Analysis & Rule
CVE-2026-12408 affects the Slim SEO plugin (versions up to 4.9.8) with a CVSS score of 4.3. Authenticated users can access private content via a vulnerable REST API endpoint. Update to version 4.9.9 to mitigate this risk.
June 30, 2026
CVE-2026-12158: RegistrationMagic <= 6.0.9.1 Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter PoC, Patch Analysis & Rule
CVE-2026-12158 affects the Custom Registration Form Builder With Submission Manager plugin (up to 6.0.9.1) with a CVSS of 8.8. This CSRF vulnerability allows privilege escalation; update to 6.0.9.2 to mitigate risks.
June 30, 2026
CVE-2026-11387: SMS Alert <= 3.9.5 Unauthenticated Privilege Escalation via Arbitrary Password Reset PoC, Patch Analysis & Rule
CVE-2026-11387 affects the Sms Alert plugin for WordPress, with a critical CVSS score of 9.8. Unauthenticated attackers can exploit this to reset user passwords. Update to version 3.9.6 to mitigate this risk.
June 30, 2026
CVE-2026-12435: Motors <= 1.4.111 Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter PoC, Patch Analysis & Rule
CVE-2026-12435 affects the Motors Car Dealership Classified Listings plugin for WordPress (up to 1.4.111). This medium severity vulnerability allows authenticated users to alter car listings. Update to version 1.4.112 to mitigate.
June 30, 2026
CVE-2026-12224: Dokan Pro <= 5.0.4 Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint PoC, Patch Analysis & Rule
CVE-2026-12224 affects Dokan Pro plugin versions up to 5.0.4, allowing authenticated attackers to escalate privileges to administrator. This high-severity vulnerability (CVSS 8.8) requires immediate patching to prevent site takeover.
June 30, 2026
CVE-2026-10096: Qi Blocks <= 1.4.9 Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter PoC, Patch Analysis & Rule
CVE-2026-10096 affects the Qi Blocks plugin for WordPress (up to version 1.4.9) with a medium severity (CVSS 4.3) IDOR vulnerability. Patch to version 1.5 to prevent unauthorized modifications by authenticated users.
June 30, 2026
CVE-2026-12732: LearnPress <= 4.4.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-12732 affects the LearnPress plugin (up to version 4.4.0) with a CVSS score of 6.4. This medium-severity Stored XSS vulnerability allows authenticated users to inject scripts. Update to version 4.4.1 to mitigate.
June 30, 2026
CVE-2026-13733: Download Manager <= 3.3.60 Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-13733 affects the Download Manager plugin for WordPress (up to 3.3.60) with a medium severity (CVSS 6.4) Stored XSS vulnerability. Update to version 3.3.61 to mitigate risks from authenticated attackers.
June 30, 2026
CVE-2026-11823: BookingPress Appointment Booking Pro <= 5.7.1 Unauthenticated SQL Injection via 'store_service_date' Parameter PoC, Patch Analysis & Rule
CVE-2026-11823 affects BookingPress Appointment Booking Pro plugin versions up to 5.7.1, allowing unauthenticated SQL injection with a CVSS score of 7.5. Users should update to the patched version to mitigate risks.
June 30, 2026
CVE-2026-1239: Ninja Forms <= 3.14.1 Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint PoC, Patch Analysis & Rule
CVE-2026-1239 affects Ninja Forms plugin version 3.14.1 with a CVSS score of 7.5. Unauthenticated attackers can access sensitive form submissions. Update to version 3.14.2 to mitigate this vulnerability.
June 30, 2026
CVE-2026-6070: WP-BusinessDirectory <= 4.0.1 Unauthenticated Arbitrary File Deletion via Path Traversal via '_filename' Parameter PoC, Patch Analysis & Rule
CVE-2026-6070 affects the WP-BusinessDirectory plugin (versions
June 30, 2026
CVE-2026-12127: WPForms <= 1.10.2 Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name PoC, Patch Analysis & Rule
CVE-2026-12127 affects WPForms Lite versions up to 1.10.2, allowing unauthenticated CRLF injection due to improper header sanitization. Upgrade to version 1.10.2.1 to mitigate this medium severity vulnerability.
June 30, 2026
CVE-2026-11981: GiveWP <= 4.15.3 Cross-Site Request Forgery PoC, Patch Analysis & Rule
CVE-2026-11981 affects the GiveWP plugin for WordPress (up to version 4.15.3) with a medium severity (CVSS 4.3) CSRF vulnerability. Update to version 4.15.4 to mitigate the risk of unauthorized email notification changes.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
