
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2025-14079: ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.5 Missing Authorization to Authenticated (Subscriber+) Settings Update PoC, Patch Analysis & Rule
Medium CVE-2025-14079 in Elex Helpdesk Customer Support Ticket System (CVSS 5.3): ELEX WordPress HelpDesk & Customer Ticketing System. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to...
March 18, 2026
CVE-2025-13192: Popup builder with Gamification <= 2.2.0 Unauthenticated SQL Injection via Multiple REST API Endpoints PoC, Patch Analysis & Rule
High CVE-2025-13192 in Popup Builder Block (CVSS 8.2): Popup builder with Gamification. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.2.1.
March 18, 2026
CVE-2026-1246: ShortPixel Image Optimizer <= 6.4.2 Authenticated (Editor+) Arbitrary File Read via 'loadFile' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-1246 in Shortpixel Image Optimiser (CVSS 4.9): ShortPixel Image Optimizer. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 6.4.3.
March 18, 2026
CVE-2025-68037: Export Media URLs <= 2.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-68037 in Export Media Urls (CVSS 6.1): Export Media URLs. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.3.
March 18, 2026
CVE-2026-0867: Essential Widgets <= 3.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes PoC, Patch Analysis & Rule
Medium CVE-2026-0867 in Essential Widgets (CVSS 6.4): Essential Widgets. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.0.1.
March 18, 2026
CVE-2025-69324: NEX-Forms <= 9.1.7 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2025-69324 in Nex Forms Express Wp Form Builder (CVSS 7.2): NEX-Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 9.1.8.
March 18, 2026
CVE-2025-67984: NPS computy <= 2.8.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2025-67984 in Nps Computy (CVSS 7.2): NPS computy. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.8.3.
March 18, 2026
CVE-2026-1268: Dynamic Widget Content <= 1.3.6 Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Content Field PoC, Patch Analysis & Rule
Medium CVE-2026-1268 in Dynamic Widget Content (CVSS 6.4): Dynamic Widget Content. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-23976: Modula Image Gallery <= 2.13.4 Authenticated (Author+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-23976 in Modula Best Grid Gallery (CVSS 6.4): Modula Image Gallery. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.13.5.
March 18, 2026
CVE-2025-67979: WPForms Google Sheet Connector <= 4.0.1 Authenticated (Subscriber+) Remote Code Execution PoC, Patch Analysis & Rule
High CVE-2025-67979 in Gsheetconnector Wpforms (CVSS 8.8): WPForms Google Sheet Connector. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.0.2.
March 18, 2026
CVE-2026-1319: Robin Image Optimizer <= 2.0.2 Authenticated (Author+) Stored Cross-Site Scripting via Image Alternative Text Field PoC, Patch Analysis & Rule
Medium CVE-2026-1319 in Robin Image Optimizer (CVSS 6.4): Robin Image Optimizer. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.0.3.
March 18, 2026
CVE-2025-68853: Contact Manager <= 9.1 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2025-68853 in Contact Manager (CVSS 8.1): Contact Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 9.1.1.
March 18, 2026
CVE-2025-68841: TopperPack – Complete Elementor Addons, Theme & CPT Builder <= 1.2.1 Unauthenticated Local File Inclusion PoC, Patch Analysis & Rule
High CVE-2025-68841 in Topper Pack (CVSS 8.1): TopperPack – Complete Elementor Addons, Theme & CPT Builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-68023: Addonify – Compare Products For WooCommerce <= 1.1.17 Missing Authorization to Unauthenticated Settings Update PoC, Patch Analysis & Rule
Medium CVE-2025-68023 in Addonify Compare Products (CVSS 5.3): Addonify – Compare Products For WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.1.18.
March 18, 2026
CVE-2026-24988: The Events Calendar Shortcode & Block <= 3.1.1 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-24988 in The Events Calendar Shortcode (CVSS 6.4): The Events Calendar Shortcode & Block. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.1.2.
March 18, 2026
CVE-2025-68024: Addonify – WooCommerce Wishlist <= 2.0.15 Missing Authorization to Unauthenticated Settings Update PoC, Patch Analysis & Rule
Medium CVE-2025-68024 in Addonify Wishlist (CVSS 5.3): Addonify – WooCommerce Wishlist. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.0.16.
March 18, 2026
CVE-2025-68834: Sync Master Sheet – Product Sync with Google Sheet for WooCommerce <= 1.1.3 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-68834 in Product Sync Master Sheet (CVSS 5.3): Sync Master Sheet – Product Sync with Google Sheet for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.1.4.
March 18, 2026
CVE-2025-68022: Plugin BlueX for WooCommerce <= 3.1.4 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-68022 in Bluex For Woocommerce (CVSS 5.3): Plugin BlueX for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-0679: Fortis for WooCommerce <= 1.2.0 Missing Authorization to Unauthenticated Arbitrary Order Status Update to Paid via 'wc-api' Endpoint PoC, Patch Analysis & Rule
Medium CVE-2026-0679 in Fortis For Woocommerce (CVSS 5.3): Fortis for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.3.0.
March 18, 2026
CVE-2025-15487: Code Explorer <= 1.4.6 Authenticated (Administrator+) Arbitrary File Read via 'file' Parameter PoC, Patch Analysis & Rule
Medium CVE-2025-15487 in Code Explorer (CVSS 4.9): Code Explorer. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
