
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-25419: UpsellWP <= 2.2.3 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-25419 affects the Checkout Upsell And Order Bumps plugin (up to v2.2.3) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized actions by authenticated users. Upgrade to v2.2.5 to mitigate risks.
March 18, 2026
CVE-2025-69365: Uroan Core <= 1.4.4 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2025-69365 affects the Uroan Core plugin for WordPress (up to version 1.4.4) with a high severity CVSS score of 7.5 due to SQL injection. Ensure to patch to prevent unauthorized database access.
March 18, 2026
CVE-2025-69366: Emerce Core <= 1.8 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2025-69366 affects the Emerce Core plugin for WordPress (up to version 1.8) with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated attackers to extract sensitive database information...
March 18, 2026
CVE-2026-1280: Frontend File Manager Plugin <= 23.5 Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter PoC, Patch Analysis & Rule
CVE-2026-1280 affects Nmedia User File Uploader (up to v23.5) with a high severity CVSS score of 7.5. Unauthenticated attackers can exploit this file upload vulnerability to share sensitive files via email. Update to v23.6.
March 18, 2026
CVE-2026-25409: JAMstack Deployments <= 1.1.1 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-25409 affects the Wp Jamstack Deployments plugin (v1.1.1) with a medium severity CVSS score of 4.3. Authenticated users can exploit a missing capability check, making patching essential to prevent unauthorized actions.
March 18, 2026
CVE-2026-1380: Bitcoin Donate Button <= 1.0 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule
CVE-2026-1380 affects the Bitcoin Donate Button plugin for WordPress (v1.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Unauthenticated attackers can alter settings if an admin is tricked into a malicious action. Patching is...
March 18, 2026
CVE-2026-1391: Vzaar Media Management <= 1.2 Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] PoC, Patch Analysis & Rule
CVE-2026-1391 affects the Vzaar Media Management plugin for WordPress (up to version 1.2) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this XSS vulnerability, making timely patching essential.
March 18, 2026
CVE-2026-0844: Simple User Registration <= 6.7 Authenticated (Subscriber+) Privilege Escalation via profile_save_field PoC, Patch Analysis & Rule
CVE-2026-0844 affects the Wp Registration plugin (up to version 6.7) with a CVSS score of 8.8. Authenticated users can escalate privileges. Update to version 6.8 to mitigate this high-severity vulnerability.
March 18, 2026
CVE-2025-14616: Recooty <= 1.0.6 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule
CVE-2025-14616 affects the Recooty plugin for WordPress (up to v1.0.6) with a medium severity (CVSS 4.3) CSRF vulnerability. Patching is essential to prevent unauthorized changes to iframe attributes.
March 18, 2026
CVE-2026-1377: imwptip <= 1.1 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule
CVE-2026-1377 reveals a medium-severity CSRF vulnerability in the Imwptip plugin for WordPress (version 1.1 and earlier). Ensure to update to the patched version to mitigate unauthorized settings changes.
March 18, 2026
CVE-2026-1398: Change WP URL <= 1.0 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule
CVE-2026-1398 affects the Change WP URL plugin (v1.0) with a CVSS score of 4.3. This medium severity CSRF vulnerability allows unauthenticated attackers to alter the WP login URL by tricking an admin. Ensure you update to the patched...
March 18, 2026
CVE-2025-15511: Rupantorpay <= 2.0.0 Missing Authorization to Unauthenticated Order Status Modification PoC, Patch Analysis & Rule
CVE-2025-15511 affects the Rupantorpay plugin for WordPress (up to v2.0.0) with a CVSS score of 5.3. Unauthenticated attackers can exploit this to modify WooCommerce order statuses. Ensure you update to the patched version.
March 18, 2026
CVE-2026-1399: WP Google Ad Manager Plugin <= 1.1.0 Authenticated (Administrator+) Stored Cross-Site Scripting via Admin Settings PoC, Patch Analysis & Rule
CVE-2026-1399 affects the WP Google Ad Manager Plugin (up to 1.1.0) with a medium severity CVSS score of 4.4. Admin-level users can exploit stored XSS vulnerabilities, so patching is essential for security.
March 18, 2026
CVE-2025-14063: SEO Links Interlinking <= 1.7.9.9.1 Reflected Cross-Site Scripting via 'google_error' Parameter PoC, Patch Analysis & Rule
CVE-2025-14063 affects the SEO Links Interlinking plugin (up to version 1.7.9.9.1) with a medium severity CVSS score of 6.1 due to reflected cross-site scripting. Update to version 1.7.9.9.2 to mitigate this risk.
March 18, 2026
CVE-2025-14283: BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.14 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-14283 affects Blockart Blocks plugin versions up to 2.2.14, allowing authenticated attackers to exploit stored XSS vulnerabilities. Upgrade to 2.2.15 to mitigate risks associated with this medium severity issue.
March 18, 2026
CVE-2026-1381: Order Minimum/Maximum Amount Limits for WooCommerce <= 4.6.8 Authenticated (Shop Manager+) Stored Cross-Site Scripting via Hide Add to Cart Content Fields PoC, Patch Analysis & Rule
CVE-2026-1381 affects the Order Minimum Amount For WooCommerce plugin (up to v4.6.8) with a medium severity (CVSS 4.4) stored XSS vulnerability. Patch to v4.6.9 to mitigate risks from authenticated attackers.
March 18, 2026
CVE-2026-1389: Document Embedder <= 2.0.4 Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Document Library Entry Deletion PoC, Patch Analysis & Rule
CVE-2026-1389 affects the Document Embedder plugin for WordPress (up to version 2.0.4) with a medium severity CVSS score of 5.3. Authenticated attackers can exploit this to manipulate Document Library entries. Update to version 2.0.5.
March 18, 2026
CVE-2026-1053: Ivory Search <= 5.5.13 Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_gcse' and 'nothing_found_text' Parameters PoC, Patch Analysis & Rule
CVE-2026-1053 affects the Ivory Search plugin (up to 5.5.13) with a CVSS score of 4.4, allowing XSS attacks via admin settings. Update to 5.5.14 to mitigate risks associated with this vulnerability.
March 18, 2026
CVE-2025-14386: Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization 2.4.4 2.5.12 Missing Authorization to Authenticated (Subscriber+) Authentication Bypass via Account Takeover PoC, Patch Analysis & Rule
CVE-2025-14386 affects the Metasync plugin (versions 2.4.4 to 2.5.12) with a CVSS score of 8.8. This high-severity authentication bypass allows attackers to log in as the first Administrator. Upgrade to version 2.5.13 to mitigate.
March 18, 2026
CVE-2026-1054: RegistrationMagic <= 6.0.7.4 Missing Authorization to Unauthenticated Arbitrary Settings Modification PoC, Patch Analysis & Rule
CVE-2026-1054 affects the Custom Registration Form Builder With Submission Manager plugin (versions
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
