Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-0912: Toret Manager <= 1.2.7 Authenticated (Subscriber+) Arbitrary Options Update via AJAX actions PoC, Patch Analysis & Rule

High CVE-2026-0912 in Toret Manager (CVSS 8.8): Toret Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-0926: Prodigy Commerce <= 3.3.0 Unauthenticated Local File Inclusion via parameters[template_name] PoC, Patch Analysis & Rule

Critical CVE-2026-0926 in Prodigy Commerce (CVSS 9.8): Prodigy Commerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.3.1.
March 18, 2026

CVE-2026-2282: Slidorion <= 1.0.2 Authenticated (Administrator+) Stored Cross-Site Scripting via Slidorion Settings PoC, Patch Analysis & Rule

Medium CVE-2026-2282 in Slidorion (CVSS 4.4): Slidorion. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-13563: Lizza LMS Pro <= 1.0.3 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule

Critical CVE-2025-13563 in Lizza Lms Pro (CVSS 9.8): Lizza LMS Pro. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-1455: Whatsiplus Scheduled Notification for Woocommerce <= 1.0.1 Cross-Site Request Forgery to 'wsnfw_save_users_settings' AJAX Action PoC, Patch Analysis & Rule

Medium CVE-2026-1455 in Whatsiplus Scheduled Notification For Woocommerce (CVSS 4.3): Whatsiplus Scheduled Notification for Woocommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-0974: Orderable <= 1.20.0 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation PoC, Patch Analysis & Rule

High CVE-2026-0974 in Orderable (CVSS 8.8): Orderable. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.20.1.
March 18, 2026

CVE-2026-1043: PostmarkApp Email Integrator <= 2.4 Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings PoC, Patch Analysis & Rule

Medium CVE-2026-1043 in Postmarkapp Email Integrator (CVSS 4.4): PostmarkApp Email Integrator. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-13413: Country Blocker for AdSense <= 1.0 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

Medium CVE-2025-13413 in Country Blocker For Adsense (CVSS 4.3): Country Blocker for AdSense. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-13864: Breeze – WordPress Cache Plugin <= 2.2.21 Missing Authorization to Cache Deletion PoC, Patch Analysis & Rule

Medium CVE-2025-13864 in Breeze (CVSS 5.3): Breeze – WordPress Cache Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.2.22.
March 18, 2026

CVE-2025-13438: Page Title, Description & Open Graph Updater <= 1.02 Cross-Site Request Forgery to Arbitrary Page Title Modification PoC, Patch Analysis & Rule

Medium CVE-2025-13438 in Page Title Description Open Graph Updater (CVSS 4.3): Page Title, Description & Open Graph Updater. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-13617: Apollo13 Framework Extension <= 1.9.8 Authenticated (Contributor+) Stored Cross-Site Scripting via `a13_alt_link` Parameter PoC, Patch Analysis & Rule

Medium CVE-2025-13617 in Apollo13 Framework Extensions (CVSS 6.4): Apollo13 Framework Extension. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-13603: WP AUDIO GALLERY <= 2.0 Authenticated (Subscriber+) Arbitrary File Read via .htaccess Manipulation PoC, Patch Analysis & Rule

High CVE-2025-13603 in Wp Audio Gallery (CVSS 8.8): WP AUDIO GALLERY. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-12975: CTX Feed – WooCommerce Product Feed Manager <= 6.6.11 Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation PoC, Patch Analysis & Rule

High CVE-2025-12975 in Webappick Product Feed For Woocommerce (CVSS 7.2): CTX Feed – WooCommerce Product Feed Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 6.6.12.
March 18, 2026

CVE-2025-12884: Advanced Ads – Ad Manager & AdSense <= 2.0.14 Missing Authorization to Authenticated (Subscriber+) Ad Placements Update PoC, Patch Analysis & Rule

Medium CVE-2025-12884 in Advanced Ads (CVSS 4.3): Advanced Ads – Ad Manager & AdSense. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.0.15.
March 18, 2026

CVE-2025-12500: Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.1 Unauthenticated Limited File Upload PoC, Patch Analysis & Rule

Medium CVE-2025-12500 in Woocommerce Checkout Manager (CVSS 5.3): Checkout Field Manager (Checkout Manager) for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 7.8.2.
March 18, 2026

CVE-2025-13587: Two Factor (2FA) Authentication via Email <= 1.9.8 Two-Factor Authentication Bypass via token PoC, Patch Analysis & Rule

Medium CVE-2025-13587 in Two Factor 2fa Via Email (CVSS 6.5): Two Factor (2FA) Authentication via Email. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.9.9.
March 18, 2026

CVE-2025-12882: Clasifico Listing <= 2.0 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule

Critical CVE-2025-12882 in Clasifico Listing (CVSS 9.8): Clasifico Listing. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-12375: Printful Integration for WooCommerce <= 2.2.11 Authenticated (Contributor+) Server-Side Request Forgery PoC, Patch Analysis & Rule

Medium CVE-2025-12375 in Printful Shipping For Woocommerce (CVSS 6.4): Printful Integration for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.2.12.
March 18, 2026

CVE-2025-11725: Aruba HiSpeed Cache <= 3.0.2 Missing Authorization to Unauthenticated Plugin's Settings Modification PoC, Patch Analysis & Rule

Medium CVE-2025-11725 in Aruba Hispeed Cache (CVSS 6.5): Aruba HiSpeed Cache. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2025-12451: Easy SVG Support <= 4.0 Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload PoC, Patch Analysis & Rule

Medium CVE-2025-12451 in Easy Svg (CVSS 6.1): Easy SVG Support. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.1.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works