
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
June 30, 2026
CVE-2026-12113: Appointment Booking Calendar <= 1.4.02 Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure PoC, Patch Analysis & Rule
CVE-2026-12113 affects the Appointment Booking Calendar plugin (up to 1.4.02) with a CVSS score of 4.3. Authenticated attackers can access sensitive customer data. Update to version 1.4.03 to mitigate this vulnerability.
June 30, 2026
CVE-2026-11988: LearnPress <= 4.3.9.1 Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter PoC, Patch Analysis & Rule
CVE-2026-11988 affects LearnPress plugin versions up to 4.3.9.1, allowing authenticated users to access sensitive course data. Upgrade to version 4.4.0 to mitigate this medium severity vulnerability.
June 29, 2026
CVE-2026-9711: EventON WordPress Virtual Event Calendar Plugin <= 5.0.11 Unauthenticated Blind SQL Injection via Search Parameter PoC, Patch Analysis & Rule
CVE-2026-9711 affects the EventON plugin (up to version 5.0.11) with a CVSS score of 9.8. This critical SQL injection vulnerability allows unauthenticated attackers to extract sensitive data. Patching is essential.
June 29, 2026
CVE-2026-8141: Ajax Load More Filters <= 3.4.1 Unauthenticated Stored Cross-Site Scripting via 'taxonomy_include_children' Field PoC, Patch Analysis & Rule
CVE-2026-8141 affects the Ajax Load More Filters plugin for WordPress, with a high severity CVSS score of 7.2. Users should update from version 3.4.1 to mitigate stored XSS risks.
June 29, 2026
CVE-2026-12240: Export User Data <= 2.2.6 Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field PoC, Patch Analysis & Rule
CVE-2026-12240 affects the Export User Data plugin for WordPress (up to 2.2.6) with a CVSS score of 8.0. Authenticated attackers can exploit this high-severity file upload vulnerability to delete arbitrary files, risking remote code...
June 29, 2026
CVE-2026-57687: Custom Field Template <= 2.7.8 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-57687 affects the Custom Field Template plugin (up to v2.7.8) with a medium severity (CVSS 6.5) SQL Injection vulnerability. Users should update to v2.8 to mitigate risks of data exposure from authenticated attacks.
June 29, 2026
CVE-2026-12073: ProfileGrid User Profiles, Groups and Communities <= 5.9.9.5 Unauthenticated Privilege Escalation via Email Overwrite PoC, Patch Analysis & Rule
CVE-2026-12073 affects the ProfileGrid User Profiles plugin (up to 5.9.9.5) with a critical CVSS score of 9.8. Unauthenticated attackers can escalate privileges via account takeover. Update to version 5.9.9.6 to mitigate this risk.
June 29, 2026
CVE-2026-11367: PixMagix <= 1.7.2 Authenticated (Author+) Path Traversal in 'layers[].id' Parameter PoC, Patch Analysis & Rule
CVE-2026-11367 affects the Pixmagix plugin (versions
June 29, 2026
CVE-2026-12560: Editorial Rating <= 4.0.5 Authenticated (Administrator+) Stored Cross-Site Scripting via 'Link URL' Field PoC, Patch Analysis & Rule
CVE-2026-12560 affects the Editorial Rating plugin for WordPress (up to version 4.0.5) with a medium severity CVSS score of 4.4. Patch to version 4.0.6 to mitigate stored XSS risks from authenticated attackers.
June 29, 2026
CVE-2026-12349: Premium Addons for KingComposer <= 1.1.1 Missing Authorization to Unauthenticated Arbitrary Custom Sidebar Creation and Deletion via 'add_custom_sidebar' and 'remove_custom_sidebar' AJAX actions PoC, Patch Analysis & Rule
CVE-2026-12349 affects the Premium Addons for KingComposer plugin (up to version 1.1.1) with a medium severity CVSS score of 5.3. Unauthenticated attackers can modify or delete custom sidebars, risking site functionality. Patching is...
June 29, 2026
CVE-2026-8944: Plugin for Google Analytics by IO technologies <= 1.1 Cross-Site Request Forgery via 'ga_id' Parameter PoC, Patch Analysis & Rule
CVE-2026-8944 affects the Io Engagement Analytics plugin (v1.1) with a medium severity CVSS score of 4.3. Unauthenticated attackers can exploit a CSRF flaw to alter Google Analytics settings, highlighting the need for immediate patching.
June 29, 2026
CVE-2026-57663: Recipe Cards For Your Food Blog from Zip Recipes <= 8.2.7 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-57663 affects the Zip Recipes plugin for WordPress (up to version 8.2.7) with a medium severity CVSS score of 6.5. Authenticated attackers can exploit this SQL injection vulnerability, making prompt patching essential.
June 29, 2026
CVE-2026-57667: Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5 Authenticated (Sales representative+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-57667 affects the Groundhogg plugin for WordPress (up to version 4.5) with a medium severity SQL injection vulnerability (CVSS 6.5). Update to version 4.5.1 to mitigate risks of data exposure.
June 29, 2026
CVE-2026-12114: Team Members <= 8.7 Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_css' Parameter PoC, Patch Analysis & Rule
CVE-2026-12114 affects the Team Showcase Supreme plugin for WordPress (up to version 8.7) with a CVSS score of 4.4. Patch to version 8.8 to mitigate Stored XSS risks from authenticated attackers.
June 29, 2026
CVE-2026-57637: Abandoned Cart Lite for WooCommerce <= 6.8.0 Cross-Site Request Forgery PoC, Patch Analysis & Rule
CVE-2026-57637 affects the WooCommerce Abandoned Cart plugin (up to v6.8.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Update to v6.8.1 to mitigate unauthorized actions by attackers.
June 29, 2026
CVE-2026-57631: Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 6.0.1 Authenticated (Administrator+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-57631 affects the Ays Popup Box plugin for WordPress (up to v6.0.1) with a medium severity CVSS score of 4.9. Admins should upgrade to v6.0.2 to mitigate the SQL injection risk that could expose sensitive database information.
June 29, 2026
CVE-2026-57645: Newsletters <= 4.13 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-57645 affects the Newsletters Lite plugin (up to version 4.13) with a medium severity CVSS score of 4.3. Ensure you update to version 4.14 to prevent unauthorized access by authenticated users.
June 29, 2026
CVE-2026-57636: wpForo Forum <= 3.0.9 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-57636 affects the wpForo plugin for WordPress, versions up to 3.0.9, with a CVSS score of 6.5. Authenticated attackers can exploit this SQL injection vulnerability to access sensitive database information. Upgrade to 3.1.0 to...
June 29, 2026
CVE-2026-57660: Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.1 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-57660 affects the Booking And Rental Manager For WooCommerce plugin (up to 2.7.1) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability, so ensure you update to the patched version.
June 29, 2026
CVE-2026-57662: Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 30.0.0 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-57662 affects the Contest Gallery plugin for WordPress (up to version 30.0.0) with a medium severity CVSS score of 6.5. Patch to version 30.0.1 to mitigate SQL injection risks from authenticated attackers.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
