Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2025-69378: Product Filter for WooCommerce <= 9.1.2 Authenticated (Shop Manager+) Privilege Escalation PoC, Patch Analysis & Rule

High CVE-2025-69378 in Prdctfltr (CVSS 7.2): Product Filter for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-69377: User Extra Fields <= 17.0 Authenticated (Subscriber+) Arbitrary File Deletion PoC, Patch Analysis & Rule

High CVE-2025-69377 in Wp User Extra Fields (CVSS 8.1): User Extra Fields. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-69376: User Extra Fields <= 17.0 Unauthenticated Arbitrary File Deletion PoC, Patch Analysis & Rule

Critical CVE-2025-69376 in Wp User Extra Fields (CVSS 9.8): User Extra Fields. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-68026: LC Wizard <= 2.1.1 Missing Authorization to Unauthenticated Settings Update PoC, Patch Analysis & Rule

Medium CVE-2025-68026 in Ghl Wizard (CVSS 5.3): LC Wizard. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.2.
March 18, 2026

CVE-2026-1927: GreenShift Animation and Page Builder Blocks <= 12.6 Missing Authorization to Authenticated (Subscriber+) Information Disclosure of AI API Keys and Stored Cross-Site Scripting via custom_css PoC, Patch Analysis & Rule

Medium CVE-2026-1927 in Greenshift Animation And Page Builder Blocks (CVSS 5.4): GreenShift - Animation and Page Builder Blocks. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 12.6.1.
March 18, 2026

CVE-2025-67990: GMap Targeting <= 1.1.7 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

High CVE-2025-67990 in Gmap Targeting (CVSS 7.2): GMap Targeting. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-68043: LottieFiles <= 3.0.0 Missing Authorization PoC, Patch Analysis & Rule

Critical CVE-2025-68043 in Lottiefiles (CVSS 9.8): LottieFiles. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-25028: ElementInvader Addons for Elementor <= 1.4.1 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-25028 in Elementinvader Addons For Elementor (CVSS 4.3): ElementInvader Addons for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.4.2.
March 18, 2026

CVE-2025-68852: Court Reservation <= 1.10.8 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2025-68852 in Court Reservation (CVSS 6.1): Court Reservation. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.10.9.
March 18, 2026

CVE-2025-68032: Advanced WC Analytics <= 3.19.0 Missing Authorization to Unauthenticated Settings Update PoC, Patch Analysis & Rule

Medium CVE-2025-68032 in Advance Wc Analytics (CVSS 4.3): Advanced WC Analytics. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-1401: Tune Library <= 1.6.3 Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via CSV Import PoC, Patch Analysis & Rule

Medium CVE-2026-1401 in Tune Library (CVSS 6.4): Tune Library. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.6.4.
March 18, 2026

CVE-2025-68862: Woo File Dropzone <= 1.1.7 Authenticated (Subscriber+) Arbitrary File Deletion PoC, Patch Analysis & Rule

Medium CVE-2025-68862 in Woo File Dropzone (CVSS 4.3): Woo File Dropzone. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-68851: Okay Toolkit <= 2.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2025-68851 in Okay Toolkit (CVSS 6.1): Okay Toolkit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-69375: Portfolio Builder <= 1.2.5 Unauthenticated Local File Inclusion PoC, Patch Analysis & Rule

High CVE-2025-69375 in Swp Portfolio (CVSS 8.1): Portfolio Builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-68863: iContact for Gravity Forms <= 1.3.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2025-68863 in Gravity Forms Icontact (CVSS 6.1): iContact for Gravity Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-68025: Addonify Floating Cart For WooCommerce <= 1.2.17 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2025-68025 in Addonify Floating Cart (CVSS 5.3): Addonify Floating Cart For WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-1294: All In One Image Viewer Block <= 1.0.2 Unauthenticated Server-Side Request Forgery via image-proxy Endpoint PoC, Patch Analysis & Rule

High CVE-2026-1294 in Image Viewer (CVSS 7.2): All In One Image Viewer Block. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.0.3.
March 18, 2026

CVE-2025-13416: ProfileGrid – User Profiles, Groups and Communities <= 5.9.7.2 Missing Authorization to Authenticated (Subscriber+) Arbitrary User Suspension PoC, Patch Analysis & Rule

Medium CVE-2025-13416 in Profilegrid User Profiles Groups And Communities (CVSS 4.3): ProfileGrid – User Profiles, Groups and Communities. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage...
March 18, 2026

CVE-2026-1654: Peter’s Date Countdown <= 2.0.0 Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] PoC, Patch Analysis & Rule

Medium CVE-2026-1654 in Peters Date Countdown (CVSS 6.1): Peter's Date Countdown. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-1271: ProfileGrid <= 5.9.7.2 Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image Modification PoC, Patch Analysis & Rule

Medium CVE-2026-1271 in Profilegrid User Profiles Groups And Communities (CVSS 5.3): ProfileGrid. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.9.7.3.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works