
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-2628: All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login <= 2.2.5 Authentication Bypass PoC, Patch Analysis & Rule
Critical CVE-2026-2628 in Login With Azure (CVSS 9.8): All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1566: LatePoint <= 5.2.7 Authenticated (Agent+) Privilege Escalation PoC, Patch Analysis & Rule
High CVE-2026-1566 in Latepoint (CVSS 8.8): LatePoint. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.2.8.
March 18, 2026
CVE-2026-3132: Master Addons for Elementor Premium <= 2.1.3 Authenticated (Subscriber+) Remote Code Execution via render_preview PoC, Patch Analysis & Rule
High CVE-2026-3132 in Master Addons Pro (CVSS 8.8): Master Addons for Elementor Premium. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-28038: Ultimate Addons for WPBakery Page Builder <= 3.21.1 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-28038 in Ultimate_VC_Addons (CVSS 4.3): Ultimate Addons for WPBakery Page Builder. Atomic Edge summarizes impact, exploitability, and patch details.
March 18, 2026
CVE-2026-28037: EventON <= 4.9.12 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-28037 in EventON (CVSS 6.1): EventON. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1542: Super Stage WP <= 1.0.1 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-1542 in Super Stage Wp (CVSS 8.1): Super Stage WP. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.0.2.
March 18, 2026
CVE-2025-13673: Tutor LMS <= 3.9.6 Unauthenticated SQL Injection via coupon_code PoC, Patch Analysis & Rule
High CVE-2025-13673 in Tutor (CVSS 7.5): Tutor LMS. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.9.7.
March 18, 2026
CVE-2026-2471: WP Mail Logging <= 1.15.0 Unauthenticated PHP Object Injection via Email Log Message Field PoC, Patch Analysis & Rule
High CVE-2026-2471 in Wp Mail Logging (CVSS 7.5): WP Mail Logging. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.16.0.
March 18, 2026
CVE-2026-28071: pixfort Core <= 3.2.22 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-28071 in Pixfort Core (CVSS 4.3): pixfort Core. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-27983: LMS Elementor Pro <= 1.0.4 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule
Critical CVE-2026-27983 in Lms Elementor Pro (CVSS 9.8): LMS Elementor Pro. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-28072: pixfort Core <= 3.2.22 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-28072 in Pixfort Core (CVSS 6.1): pixfort Core. Atomic Edge summarizes impact, exploitability, and patch details.
March 18, 2026
CVE-2026-28102: UberSlider Classic <= 2.5 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-28102 in UberSlider_classic (CVSS 6.1): UberSlider Classic. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-28100: UberSlider PerpetuumMobile <= 2.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-28100 in UberSlider_perpetuummobile (CVSS 6.1): UberSlider PerpetuumMobile. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-2269: Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload PoC, Patch Analysis & Rule
High CVE-2026-2269 in Uncanny Automator (CVSS 7.2): Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update...
March 18, 2026
CVE-2026-28099: UberSlider Ultra <= 2.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-28099 in UberSlider_ultra (CVSS 6.1): UberSlider Ultra. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-28101: UberSlider MouseInteraction <= 2.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-28101 in UberSlider_mouseinteraction (CVSS 6.1): UberSlider MouseInteraction. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-27984: Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets <= 4.1.3 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule
High CVE-2026-27984 in Widget Options (CVSS 8.8): Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage...
March 18, 2026
CVE-2026-2831: MailArchiver <= 4.5.0 Authenticated (Admininistrator+) SQL Injection via 'logid' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-2831 in Mailarchiver (CVSS 4.9): MailArchiver. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.5.1.
March 18, 2026
CVE-2026-1305: Japanized for WooCommerce <= 2.8.4 Missing Authorization to Unauthenticated Paidy Order Manipulation PoC, Patch Analysis & Rule
Medium CVE-2026-1305 in Woocommerce For Japan (CVSS 5.3): Japanized for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.8.5.
March 18, 2026
CVE-2026-2362: WP Accessibility <= 2.3.1 Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via 'alt' Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-2362 in Wp Accessibility (CVSS 6.4): WP Accessibility. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.3.2.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
