
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
June 29, 2026
CVE-2026-57643: WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars <= 3.9.1 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-57643 affects the WP Post Author plugin (up to version 3.9.1) with a medium severity score of 6.5. Authenticated attackers can exploit SQL injection to extract sensitive data. Update to the patched version to mitigate risks.
June 29, 2026
CVE-2026-57632: Email Marketing for WooCommerce by Omnisend <= 1.19.0 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-57632 affects the Omnisend Connect plugin for WordPress (up to version 1.19.0) with a CVSS score of 4.3. Patch to version 1.19.1 to mitigate unauthorized access risks.
June 28, 2026
CVE-2026-54821: Visual Link Preview <= 2.3.1 Authenticated (Subscriber+) Sensitive Information Exposure PoC, Patch Analysis & Rule
CVE-2026-54821 affects the Visual Link Preview plugin (up to version 2.3.1) with a CVSS score of 4.3. Authenticated attackers can access sensitive data. Upgrade to version 2.4.0 to mitigate this risk.
June 28, 2026
CVE-2026-54829: WP Photo Album Plus <= 9.1.13.005 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54829 affects WP Photo Album Plus versions up to 9.1.13.005 with a high severity CVSS score of 7.5. Unauthenticated SQL injection allows attackers to extract sensitive data; update to version 9.2.01.001 to mitigate.
June 28, 2026
CVE-2026-54817: MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-54817 affects the Mstore Api plugin for WordPress (up to version 4.18.4) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability, so patching is essential.
June 28, 2026
CVE-2026-54818: SlimStat Analytics <= 5.4.11 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54818 affects the SlimStat Analytics plugin for WordPress (up to 5.4.11) with a medium severity CVSS score of 6.5. Authenticated users can exploit SQL injection vulnerabilities; update to 5.4.12 to mitigate risks.
June 28, 2026
CVE-2026-54814: Motors – Car Dealership & Classified Listings Plugin <= 1.4.109 Authenticated (Subscriber+) Local File Inclusion PoC, Patch Analysis & Rule
CVE-2026-54814 affects the Motors Car Dealership Classified Listings plugin (up to v1.4.109) with a CVSS score of 7.5. Patch to v1.4.110 to mitigate the high-risk Local File Inclusion vulnerability that allows unauthorized file execution.
June 28, 2026
CVE-2026-54824: Quads Ads Manager for Google AdSense <= 3.0.3 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
CVE-2026-54824 affects Quick Adsense Reloaded plugin versions up to 3.0.3 with a medium severity (CVSS 5.3). Patch to version 3.0.4 to mitigate sensitive information exposure risks.
June 28, 2026
CVE-2026-54826: SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.6 Authenticated (Subscriber+) Insecure Direct Object Reference PoC, Patch Analysis & Rule
CVE-2026-54826 affects the SupportCandy plugin (up to v3.4.6) with a CVSS score of 4.3. Authenticated users can exploit this IDOR vulnerability, so upgrade to v3.4.7 to mitigate risks.
June 28, 2026
CVE-2026-54812: Motors – Car Dealership & Classified Listings Plugin <= 1.4.109 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54812 affects the Motors Car Dealership Classified Listings plugin for WordPress (up to version 1.4.109) with a CVSS score of 7.5. Unauthenticated SQL injection can lead to data exposure; upgrade to version 1.4.110 to mitigate.
June 28, 2026
CVE-2026-54825: wpDataTables (Premium) <= 7.4 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54825 reveals a high-severity SQL injection vulnerability in the wpDataTables plugin for WordPress, affecting versions up to 7.4. Unauthenticated attackers can exploit this flaw to access sensitive database information.
June 28, 2026
CVE-2026-54830: Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.19 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-54830 affects the Restaurant Reservations plugin (up to v2.7.19) with a CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability. Update to v2.7.20 to mitigate the risk.
June 28, 2026
CVE-2026-54834: Object Cache 4 everyone <= 2.3.2 Information Exposure PoC, Patch Analysis & Rule
CVE-2026-54834 affects Object Cache 4 Everyone plugin versions up to 2.3.2, exposing sensitive data to unauthenticated attackers. Upgrade to 2.3.3 to mitigate this medium severity vulnerability (CVSS 5.3).
June 28, 2026
CVE-2026-54828: Motors – Car Dealership & Classified Listings Plugin <= 1.4.109 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-54828 affects the Motors Car Dealership Classified Listings plugin (up to v1.4.109) with a medium severity (CVSS 5.3) vulnerability. Patch to v1.4.110 to prevent unauthorized access by attackers.
June 28, 2026
CVE-2026-54822: SALESmanago & Leadoo <= 3.11.2 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54822 affects the SALESmanago plugin (up to version 3.11.2) with a medium severity (CVSS 6.5) SQL injection vulnerability. Users should upgrade to version 3.11.3 to mitigate the risk of data exposure.
June 28, 2026
CVE-2026-54813: SureDash – Community, Courses & Member Dashboard <= 1.8.0 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54813 affects the SureDash plugin for WordPress (up to v1.8.0) with a medium severity (CVSS 6.5) SQL injection vulnerability. Users should upgrade to v1.8.1 to mitigate risks of data exposure.
June 28, 2026
CVE-2026-54820: JetBooking <= 4.0.4.1 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54820 affects the Jet Booking plugin for WordPress (up to v4.0.4.1) with a high severity CVSS score of 7.5. Unauthenticated SQL injection allows attackers to access sensitive data; patch immediately.
June 28, 2026
CVE-2026-54831: GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.162 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54831 affects the GeoDirectory plugin (up to version 2.8.162) with a high severity SQL injection vulnerability (CVSS 7.5). Update to version 2.8.163 to mitigate risks of unauthorized data access.
June 28, 2026
CVE-2026-54816: Advanced Ads – Ad Manager & AdSense <= 2.0.21 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule
CVE-2026-54816 affects the Advanced Ads plugin for WordPress (up to version 2.0.21) with a CVSS score of 8.3. Authenticated attackers can exploit this high-severity RCE vulnerability. Update to version 2.0.22 to mitigate risks.
June 28, 2026
CVE-2026-54815: Cargo Shipping Location for WooCommerce <= 5.6 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54815 reveals a high severity SQL injection vulnerability in the Cargo Shipping Location for WooCommerce plugin, affecting versions up to 5.6. Users should upgrade to version 5.7 to mitigate risks of data exposure.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
