
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1929: Advanced Woo Labels <= 2.37 Authenticated (Contributor+) Remote Code Execution via 'callback' Parameter PoC, Patch Analysis & Rule
High CVE-2026-1929 in Advanced Woo Labels (CVSS 8.8): Advanced Woo Labels. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.37.
March 18, 2026
CVE-2026-2416: Geo Mashup <= 1.13.17 Unauthenticated SQL Injection via 'sort' Parameter PoC, Patch Analysis & Rule
High CVE-2026-2416 in Geo Mashup (CVSS 7.5): Geo Mashup. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.13.18.
March 18, 2026
CVE-2026-1614: Rise Blocks – A Complete Gutenberg Page Builder <= 3.7 Authenticated (Contributor+) Stored Cross-Site Scripting via Site Identity Block Attributes PoC, Patch Analysis & Rule
Medium CVE-2026-1614 in Rise Blocks (CVSS 6.4): Rise Blocks – A Complete Gutenberg Page Builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1916: WPGSI: Spreadsheet Integration <= 3.8.3 Missing Authorization to Unauthenticated Arbitrary Post Creation and Deletion via Forged Base64 Token PoC, Patch Analysis & Rule
High CVE-2026-1916 in Wpgsi (CVSS 7.5): WPGSI: Spreadsheet Integration. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.8.4.
March 18, 2026
CVE-2026-2479: Responsive Lightbox & Gallery <= 2.7.1 Authenticated (Author+) Server-Side Request Forgery via Remote Library Image Upload PoC, Patch Analysis & Rule
Medium CVE-2026-2479 in Responsive Lightbox (CVSS 5.0): Responsive Lightbox & Gallery. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.7.2.
March 18, 2026
CVE-2026-27379: NextScripts: Social Networks Auto-Poster <= 4.4.7 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-27379 in Social Networks Auto Poster Facebook Twitter G (CVSS 7.5): NextScripts: Social Networks Auto-Poster. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-27374: WooCommerce Order Details <= 3.1 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-27374 in Woocommerce Order Details (CVSS 5.3): WooCommerce Order Details. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-27373: Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.2.3 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2026-27373 in Tablesome (CVSS 6.5): Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-27370: Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.5.1 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2026-27370 in Chaty (CVSS 5.3): Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call.... Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage...
March 18, 2026
CVE-2026-27384: W3 Total Cache <= 2.9.1 Unauthenticated Arbitrary Code Execution PoC, Patch Analysis & Rule
Critical CVE-2026-27384 in W3 Total Cache (CVSS 9.8): W3 Total Cache. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.9.2.
March 18, 2026
CVE-2026-27385: DesignThemes Portfolio <= 1.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-27385 in Designthemes Portfolio (CVSS 6.1): DesignThemes Portfolio. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-23546: Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.4 Authenticated (Subscriber+) Sensitive Data Exposure PoC, Patch Analysis & Rule
Medium CVE-2026-23546 in Classified Listing (CVSS 4.3): Classified Listing – AI-Powered Classified ads & Business Directory Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.3.5.
March 18, 2026
CVE-2026-27397: Really Simple Security Pro <= 9.5.4.0 Authenticated (Subscriber+) Insecure Direct Object Reference PoC, Patch Analysis & Rule
Medium CVE-2026-27397 in Really Simple Ssl Pro (CVSS 4.3): Really Simple Security Pro. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-27428: Eagle Booking <= 1.3.4.3 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2026-27428 in Eagle Booking (CVSS 6.5): Eagle Booking. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-27396: Directory Pro <= 2.5.6 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-27396 in Directory Pro (CVSS 5.3): Directory Pro. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-27389: WeDesignTech Ultimate Booking Addon <= 1.0.1 Authentication Bypass PoC, Patch Analysis & Rule
Critical CVE-2026-27389 in Wedesigntech Ultimate Booking Addon (CVSS 9.8): WeDesignTech Ultimate Booking Addon. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-27390: WeDesignTech Ultimate Booking Addon <= 1.0.1 Authenticated (Subscriber+) Authentication Bypass PoC, Patch Analysis & Rule
High CVE-2026-27390 in Wedesigntech Ultimate Booking Addon (CVSS 8.8): WeDesignTech Ultimate Booking Addon. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-27413: Profile Builder Pro <= 3.13.9 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
High CVE-2026-27413 in Profile Builder Pro (CVSS 7.5): Profile Builder Pro. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-27406: My Tickets – Accessible Event Ticketing <= 2.1.0 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2026-27406 in My Tickets (CVSS 5.3): My Tickets – Accessible Event Ticketing. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.1.
March 18, 2026
CVE-2026-27411: SiteGuard WP Plugin <= 1.7.9 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-27411 in Siteguard (CVSS 5.3): SiteGuard WP Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
