
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-24941: WP Job Portal <= 2.4.4 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24941 in Wp Job Portal (CVSS 5.3): WP Job Portal. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.4.5.
March 18, 2026
CVE-2025-67624: Optimize More! – Images <= 1.1.3 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-67624 in Optimize More Images (CVSS 5.3): Optimize More! – Images. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1730: OS DataHub Maps <= 1.8.3 Authenticated (Author+) Arbitrary File Upload PoC, Patch Analysis & Rule
High CVE-2026-1730 in Os Datahub Maps (CVSS 8.8): OS DataHub Maps. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.8.4.
March 18, 2026
CVE-2026-0617: LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2026-0617 in Latepoint (CVSS 7.2): LatePoint – Calendar Booking Plugin for Appointments and Events. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.2.6.
March 18, 2026
CVE-2026-1371: Tutor LMS <= 3.9.5 Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action PoC, Patch Analysis & Rule
Medium CVE-2026-1371 in Tutor (CVSS 5.3): Tutor LMS. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.9.6.
March 18, 2026
CVE-2026-1375: Tutor LMS <= 3.9.5 Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion PoC, Patch Analysis & Rule
High CVE-2026-1375 in Tutor (CVSS 8.1): Tutor LMS. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.9.6.
March 18, 2026
CVE-2026-1058: Form Maker by 10Web <= 1.15.35 Unauthenticated Stored Cross-Site Scripting via Hidden Field PoC, Patch Analysis & Rule
High CVE-2026-1058 in Form Maker (CVSS 7.1): Form Maker by 10Web. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.15.36.
March 18, 2026
CVE-2026-1065: Form Maker by 10Web <= 1.15.35 Unauthenticated Stored Cross-Site Scripting via SVG file PoC, Patch Analysis & Rule
High CVE-2026-1065 in Form Maker (CVSS 7.2): Form Maker by 10Web. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.15.36.
March 18, 2026
CVE-2026-1210: Happy Addons for Elementor <= 3.20.7 Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field PoC, Patch Analysis & Rule
Medium CVE-2026-1210 in Happy Elementor Addons (CVSS 6.4): Happy Addons for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.20.8.
March 18, 2026
CVE-2026-1447: Mail Mint <= 1.19.2 Cross-Site Request Forgery to Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-1447 in Mail Mint (CVSS 5.4): Mail Mint. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.19.3.
March 18, 2026
CVE-2026-25024: ThirstyAffiliates <= 3.11.9 Cross-Site Request Forgery PoC, Patch Analysis & Rule
Medium CVE-2026-25024 in Thirstyaffiliates (CVSS 4.3): ThirstyAffiliates. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.11.10.
March 18, 2026
CVE-2025-14274: Unlimited Elements for Elementor <= 2.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Border Hero Widget PoC, Patch Analysis & Rule
Medium CVE-2025-14274 in Unlimited Elements For Elementor (CVSS 5.4): Unlimited Elements for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-0909: WP ULike <= 4.8.3.1 Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Log Deletion via 'id' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-0909 in Wp Ulike (CVSS 5.3): WP ULike. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.0.0.
March 18, 2026
CVE-2026-25326: CMSMasters Content Composer <= 1.4.5 Authenticated (Contributor+) Local File Inclusion PoC, Patch Analysis & Rule
High CVE-2026-25326 in Cmsmasters Content Composer (CVSS 7.5): CMSMasters Content Composer. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-25023: Run Contests, Raffles, and Giveaways with ContestsWP <= 2.0.7 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2026-25023 in Contest Code Checker (CVSS 5.3): Run Contests, Raffles, and Giveaways with ContestsWP. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-0950: Spectra Gutenberg Blocks <= 2.19.17 Unauthenticated Information Disclosure in Sensitive Data PoC, Patch Analysis & Rule
Medium CVE-2026-0950 in Ultimate Addons For Gutenberg (CVSS 5.3): Spectra Gutenberg Blocks. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.19.18.
March 18, 2026
CVE-2026-1369: Conditional CAPTCHA <= 4.0.0 Unauthenticated Open Redirect PoC, Patch Analysis & Rule
Medium CVE-2026-1369 in Wp Conditional Captcha (CVSS 5.3): Conditional CAPTCHA. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-23978: Gyan Elements <= 2.2.1 Authenticated (Contributor+) Local File Inclusion PoC, Patch Analysis & Rule
High CVE-2026-23978 in Gyan Elements (CVSS 7.5): Gyan Elements. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-15525: Ajax Load More – Infinite Scroll, Lazy Load & Load More <= 7.8.1 Incorrect Authorization to Unauthenticated Private/Draft Post Title and Excerpt Exposure PoC, Patch Analysis & Rule
Medium CVE-2025-15525 in Ajax Load More (CVSS 5.3): Ajax Load More – Infinite Scroll, Lazy Load & Load More. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 7.8.2.
March 18, 2026
CVE-2025-15510: NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 Missing Authorization to Unauthenticated Sensitive Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2025-15510 in Nex Forms Express Wp Form Builder (CVSS 5.3): NEX-Forms – Ultimate Forms Plugin for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 9.1.9.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
