
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1310: Simple calendar for Elementor <= 1.6.6 Missing Authorization to Unauthenticated Arbitrary Calendar Entry Deletion PoC, Patch Analysis & Rule
CVE-2026-1310 affects the Simple Calendar For Elementor plugin (up to v1.6.6) with a CVSS score of 5.3. Unauthenticated attackers can delete calendar entries; update to v1.6.7 to mitigate this risk.
March 18, 2026
CVE-2025-12709: Interactions – Create Interactive Experiences in the Block Editor <= 1.3.1 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-12709 affects the Interactions plugin for WordPress (up to v1.3.1) with a medium severity CVSS score of 6.4. Users should update to v1.3.2 to mitigate the stored XSS vulnerability.
March 18, 2026
CVE-2026-0825: Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export PoC, Patch Analysis & Rule
CVE-2026-0825 affects the Contact Form Entries plugin (up to v1.4.5) with a medium severity (CVSS 5.3) authentication bypass, allowing unauthenticated access to sensitive data. Update to v1.4.6 to mitigate this risk.
March 18, 2026
CVE-2026-1400: AI Engine <= 3.3.2 Authenticated (Editor+) Arbitrary File Upload via 'filename' Parameter in update_media_metadata Endpoint PoC, Patch Analysis & Rule
CVE-2026-1400 affects the Ai Engine plugin (up to v3.3.2) with a CVSS score of 7.2. This high-severity file upload vulnerability allows authenticated attackers to execute arbitrary PHP code. Update to v3.3.3 to mitigate risks.
March 18, 2026
CVE-2025-9082: WPBITS Addons For Elementor <= 1.8 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-9082 affects the WPBITS Addons For Elementor plugin (up to v1.8) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should update to v1.8.1 to mitigate risks from authenticated attackers.
March 18, 2026
CVE-2026-1083: Appointment Hour Booking – Booking Calendar <= 1.5.60 Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration PoC, Patch Analysis & Rule
CVE-2026-1083 affects the Appointment Hour Booking plugin (up to v1.5.60) with a medium severity CVSS score of 4.4. Admins should upgrade to v1.5.61 to mitigate stored XSS risks in multi-site installations.
March 18, 2026
CVE-2026-0832: New User Approve <= 3.2.2 Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosure PoC, Patch Analysis & Rule
CVE-2026-0832 affects the New User Approve plugin (up to v3.2.2) with a CVSS score of 7.3. Unauthenticated attackers can exploit this vulnerability for remote code execution. Update to v3.2.3 to mitigate risks.
March 18, 2026
CVE-2026-1244: Forms Bridge <= 4.2.5 Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1244 affects the Forms Bridge plugin (up to 4.2.5) with a medium severity (CVSS 6.4) Stored XSS vulnerability. Update to version 4.3.0 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026
CVE-2025-8072: Target Video Easy Publish <= 3.8.8 Authenticated (Contributor+) Stored Cross-Site Scripting via placeholder_img Parameter PoC, Patch Analysis & Rule
CVE-2025-8072 affects the Brid Video Easy Publish plugin (up to v3.8.8) with a medium severity CVSS score of 6.4. Authenticated users can exploit stored XSS vulnerabilities, so update to v3.8.9 to mitigate risks.
March 18, 2026
CVE-2026-1298: Easy Replace Image <= 3.5.2 Missing Authorization to Authenticated (Contributor+) Arbitrary Attachment Replacement PoC, Patch Analysis & Rule
CVE-2026-1298 affects the Easy Replace Image plugin (up to 3.5.2) with a medium severity CVSS of 5.3. Authenticated users can replace images from external URLs, risking site defacement. Update to version 3.5.3 to mitigate.
March 18, 2026
CVE-2025-14610: TableMaster for Elementor <= 1.3.6 Authenticated (Author+) Server-Side Request Forgery via 'csv_url' Parameter PoC, Patch Analysis & Rule
CVE-2025-14610 affects Tablemaster for Elementor (up to 1.3.6) with a CVSS score of 7.2. Authenticated users can exploit SSRF to access sensitive files. Update to version 1.3.8 to mitigate this risk.
March 18, 2026
CVE-2025-69304: Allmart <= 1.1 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2025-69304 affects the Allmart Core plugin (version 1.1) with a high severity CVSS score of 7.5. Unauthenticated SQL injection can lead to data extraction; users should update to the patched version to mitigate risks.
March 18, 2026
CVE-2025-14865: Passster – Password Protect Pages and Content <= 4.2.24 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode PoC, Patch Analysis & Rule
CVE-2025-14865 affects the Content Protector plugin for WordPress (up to version 4.2.24) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability; update to version 4.2.25 to mitigate risks.
March 18, 2026
CVE-2025-67973: Sunshine Photo Cart <= 3.5.6.2 Missing Authorization PoC, Patch Analysis & Rule
CVE-2025-67973 affects the Sunshine Photo Cart plugin (up to v3.5.6.2) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Update to v3.5.7.1 to mitigate risks of data manipulation and denial of service.
March 18, 2026
CVE-2026-0746: AI Engine <= 3.3.2 Authenticated (Subscriber+) Server-Side Request Forgery PoC, Patch Analysis & Rule
CVE-2026-0746 affects the Ai Engine plugin for WordPress (up to v3.3.2) with a medium severity (CVSS 6.4) SSRF vulnerability. Update to v3.3.3 to mitigate risks from authenticated attackers making arbitrary web requests.
March 18, 2026
CVE-2025-68048: NextMove Lite <= 2.23.0 Missing Authorization PoC, Patch Analysis & Rule
CVE-2025-68048 affects Woo Thank You Page Nextmove Lite (up to v2.23.0) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Update to v2.24.0 to mitigate this risk.
March 18, 2026
CVE-2025-68069: Directorist <= 8.5.8 Missing Authorization PoC, Patch Analysis & Rule
CVE-2025-68069 affects the Directorist plugin (up to 8.5.8) with a medium severity CVSS score of 4.3. Authenticated attackers can exploit a missing capability check for unauthorized password resets. Update to 8.5.9 to mitigate this risk.
March 18, 2026
CVE-2025-68021: ConveyThis <= 269.1 Missing Authorization PoC, Patch Analysis & Rule
CVE-2025-68021 affects the ConveyThis Translate plugin for WordPress (up to version 269.1) with a medium severity CVSS score of 5.3. Ensure you patch to prevent unauthorized access by unauthenticated attackers.
March 18, 2026
CVE-2025-14795: Stop Spammers Classic <= 2026.1 Cross-Site Request Forgery via Email Allowlist PoC, Patch Analysis & Rule
CVE-2025-14795 affects the Stop Spammer Registrations Plugin, with a CVSS score of 4.3. It allows unauthenticated attackers to exploit CSRF vulnerabilities. Ensure you update to the patched version to mitigate this risk.
March 18, 2026
CVE-2025-69323: Slimstat Analytics <= 5.3.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-69323 affects the Slimstat Analytics plugin for WordPress (up to version 5.3.2) with a medium severity CVSS score of 6.1 due to reflected XSS. Update to version 5.3.3 to mitigate risks from potential attacks.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
