Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-23799: Tutor LMS – eLearning and online course solution <= 3.9.5 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-23799 in Tutor (CVSS 4.3): Tutor LMS – eLearning and online course solution. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.9.6.
March 18, 2026

CVE-2026-22390: Builderall for WordPress <= 3.0.1 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule

High CVE-2026-22390 in Builderall Cheetah For Wp (CVSS 8.8): Builderall for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-2506: EM Cost Calculator <= 2.3.1 Unauthenticated Stored Cross-Site Scripting via 'customer_name' PoC, Patch Analysis & Rule

Medium CVE-2026-2506 in Cost Calculator (CVSS 6.1): EM Cost Calculator. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-27354: WooCommerce Coming Soon Product with Countdown <= 5.0 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2026-27354 in Woo Coming Soon Product (CVSS 6.4): WooCommerce Coming Soon Product with Countdown. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-23802: AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.3.2 Authenticated (Editor+) Arbitrary File Upload PoC, Patch Analysis & Rule

High CVE-2026-23802 in Ai Engine (CVSS 7.2): AI Engine – The Chatbot, AI Framework & MCP for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.3.3.
March 18, 2026

CVE-2025-69343: Theater for WordPress <= 0.19 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2025-69343 in Theatre (CVSS 6.4): Theater for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-69338: Riode Core <= 1.6.26 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2025-69338 in Riode Core (CVSS 7.5): Riode Core. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-2499: Custom Logo <= 2.2 Authenticated (Administrator+) Stored Cross-Site Scripting via Logo Path Setting PoC, Patch Analysis & Rule

Medium CVE-2026-2499 in Custom Logo (CVSS 4.4): Custom Logo. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-23798: PowerPress Podcasting plugin by Blubrry <= 11.15.10 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule

High CVE-2026-23798 in Powerpress (CVSS 7.5): PowerPress Podcasting plugin by Blubrry. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 11.15.11.
March 18, 2026

CVE-2026-2694: The Events Calendar <= 6.15.16 Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API PoC, Patch Analysis & Rule

Medium CVE-2026-2694 in The Events Calendar (CVSS 5.4): The Events Calendar. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 6.15.16.1.
March 18, 2026

CVE-2026-27359: Awa Plugins <= 1.4.4 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2026-27359 in Awa Plugins (CVSS 6.1): Awa Plugins. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-69340: WeDesignTech Ultimate Booking Addon <= 1.0.3 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2025-69340 in Wedesigntech Ultimate Booking Addon (CVSS 5.3): WeDesignTech Ultimate Booking Addon. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-27361: Responsive Posts Carousel WordPress Plugin <= 15.1 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-27361 in Responsive Posts Carousel Pro (CVSS 5.3): Responsive Posts Carousel WordPress Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-2410: Disable Admin Notices – Hide Dashboard Notifications <= 1.4.2 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule

Medium CVE-2026-2410 in Disable Admin Notices (CVSS 4.3): Disable Admin Notices – Hide Dashboard Notifications. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.4.3.
March 18, 2026

CVE-2026-27363: Bakery Autoresponder Addon <= 1.0.6 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

High CVE-2026-27363 in Vc Autoresponder Addon (CVSS 7.2): Bakery Autoresponder Addon. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-27344: Scientific and Interactive Blocks – inseri core <= 1.0.5 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-27344 in Inseri Core (CVSS 5.3): Scientific and Interactive Blocks – inseri core. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-27362: Bakery Autoresponder Addon <= 1.0.6 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-27362 in Vc Autoresponder Addon (CVSS 5.3): Bakery Autoresponder Addon. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-2301: Post Duplicator <= 3.0.8 Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-2301 in Post Duplicator (CVSS 4.3): Post Duplicator. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.0.9.
March 18, 2026

CVE-2025-14742: WP Recipe Maker <= 10.2.3 Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure PoC, Patch Analysis & Rule

Medium CVE-2025-14742 in Wp Recipe Maker (CVSS 4.3): WP Recipe Maker. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 10.3.0.
March 18, 2026

CVE-2026-2367: Secure Copy Content Protection and Content Locking <= 5.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute PoC, Patch Analysis & Rule

Medium CVE-2026-2367 in Secure Copy Content Protection (CVSS 6.4): Secure Copy Content Protection and Content Locking. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.0.2.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works