
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2025-14903: Simple Crypto Shortcodes <= 1.0.2 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule
Medium CVE-2025-14903 in Simple Crypto Shortcodes (CVSS 4.3): Simple Crypto Shortcodes. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-13374: Kalrav AI Agent <= 2.3.3 Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action PoC, Patch Analysis & Rule
Critical CVE-2025-13374 in Kalrav Ai Agent (CVSS 9.8): Kalrav AI Agent. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-14629: Alchemist Ajax Upload <= 1.1 Missing Authorization to Unauthenticated Arbitrary Media File Deletion PoC, Patch Analysis & Rule
Medium CVE-2025-14629 in Alchemist Ajax Upload (CVSS 5.3): Alchemist Ajax Upload. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-24994: Sunshine Photo Cart <= 3.5.7.2 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24994 in Sunshine Photo Cart (CVSS 5.3): Sunshine Photo Cart. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.5.7.3.
March 18, 2026
CVE-2026-24991: Extensions For CF7 <= 3.4.0 Authenticated (Contributor+) Insecure Direct Object Reference PoC, Patch Analysis & Rule
Medium CVE-2026-24991 in Extensions For Cf7 (CVSS 4.3): Extensions For CF7. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.4.1.
March 18, 2026
CVE-2025-68848: amr cron manager <= 2.3 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2025-68848 in Amr Cron Manager (CVSS 7.2): amr cron manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-12836: VK Google Job Posting Manager <= 1.2.23 Authenticated (Author+) Stored Cross-Site Scripting via Job Description Field PoC, Patch Analysis & Rule
Medium CVE-2025-12836 in Vk Google Job Posting Manager (CVSS 6.4): VK Google Job Posting Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.2.24.
March 18, 2026
CVE-2025-68999: Happy Addons for Elementor <= 3.20.4 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2025-68999 in Happy Elementor Addons (CVSS 6.5): Happy Addons for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.20.6.
March 18, 2026
CVE-2026-24548: Radio Player <= 2.0.91 Unauthenticated Server-Side Request Forgery PoC, Patch Analysis & Rule
High CVE-2026-24548 in Radio Player (CVSS 7.2): Radio Player. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1251: SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 Authenticated (Subscriber+) Insecure Direct Object Reference PoC, Patch Analysis & Rule
Medium CVE-2026-1251 in Supportcandy (CVSS 5.4): SupportCandy – Helpdesk & Customer Support Ticket System. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.4.5.
March 18, 2026
CVE-2026-1720: WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation <= 1.4.24 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation PoC, Patch Analysis & Rule
High CVE-2026-1720 in Optin (CVSS 8.8): WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.4.25.
March 18, 2026
CVE-2026-24963: Booking for Appointments and Events Calendar – Amelia <= 1.2.38 Authenticated (Employee+) Privilege Escalation PoC, Patch Analysis & Rule
High CVE-2026-24963 in Ameliabooking (CVSS 8.8): Booking for Appointments and Events Calendar – Amelia. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.0.
March 18, 2026
CVE-2026-3058: Seraphinite Accelerator <= 2.28.14 Authenticated (Subscriber+) Exposure of Sensitive Information to an Unauthorized Actor PoC, Patch Analysis & Rule
Medium CVE-2026-3058 in Seraphinite Accelerator (CVSS 4.3): Seraphinite Accelerator. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.28.15.
March 18, 2026
CVE-2026-2355: My Calendar – Accessible Event Manager <= 3.7.3 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
Medium CVE-2026-2355 in My Calendar (CVSS 6.4): My Calendar – Accessible Event Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-22479: Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress <= 2.2.0 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-22479 in Easy Post Submission (CVSS 5.3): Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
March 18, 2026
CVE-2026-3056: Seraphinite Accelerator <= 2.28.14 Missing Authorization to Authenticated (Subscriber+) Log Clearing PoC, Patch Analysis & Rule
Medium CVE-2026-3056 in Seraphinite Accelerator (CVSS 4.3): Seraphinite Accelerator. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.28.15.
March 18, 2026
CVE-2026-1706: All-in-One Video Gallery <= 4.7.1 Reflected Cross-Site Scripting via 'vi' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-1706 in All In One Video Gallery (CVSS 6.1): All-in-One Video Gallery. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.7.5.
March 18, 2026
CVE-2023-7337: JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 Unauthenticated SQL Injection via ‘js-support-ticket-token-tkstatus’ Cookie PoC, Patch Analysis & Rule
High CVE-2023-7337 in Js Support Ticket (CVSS 7.5): JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via.... Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
March 18, 2026
CVE-2026-1674: Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema() PoC, Patch Analysis & Rule
Medium CVE-2026-1674 in Gutena Forms (CVSS 6.5): Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage...
March 18, 2026
CVE-2026-2732: Enable Media Replace <= 4.1.7 Improper Authorization to Authenticated (Author+) Arbitrary Attachment Change via Background Replace PoC, Patch Analysis & Rule
Medium CVE-2026-2732 in Enable Media Replace (CVSS 5.4): Enable Media Replace. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.1.8.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
