Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2025-68842: Widget Logic Visual <= 1.52 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-68842 affects the Widget Logic Visual plugin (up to version 1.52) with a CVSS score of 6.1. Unauthenticated attackers can exploit this XSS vulnerability, so ensure you update to the patched version to mitigate risks.
March 18, 2026

CVE-2025-69302: DesignThemes Core Features <= 2.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-69302 affects the DesignThemes Core Features plugin (up to v2.3) with a medium severity CVSS score of 6.1. Users should update to the patched version to mitigate the risk of reflected XSS attacks.
March 18, 2026

CVE-2025-67975: aDirectory <= 3.0.3 Missing Authorization PoC, Patch Analysis & Rule

CVE-2025-67975 affects the aDirectory plugin (up to v3.0.3) with a CVSS score of 4.3. This medium severity vulnerability allows authenticated users to perform unauthorized actions. Upgrade to v3.0.4 to mitigate.
March 18, 2026

CVE-2025-69297: Aardvark <= 2.19 Missing Authorization PoC, Patch Analysis & Rule

CVE-2025-69297 affects the Aardvark Plugin (up to version 2.19) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this flaw, so ensure you update to the patched version to mitigate risks.
March 18, 2026

CVE-2025-67974: WPLegalPages <= 3.5.4 Missing Authorization PoC, Patch Analysis & Rule

CVE-2025-67974 affects WP Legal Pages plugin versions up to 3.5.4, allowing unauthorized access due to a missing capability check. Upgrade to 3.5.5 to mitigate this medium severity vulnerability.
March 18, 2026

CVE-2025-68880: Simple Archive Generator <= 5.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-68880 affects the Simple Archive Generator plugin for WordPress (up to version 5.2) with a medium severity CVSS score of 6.1. Users should update to the patched version to mitigate the reflected XSS risk.
March 18, 2026

CVE-2025-68845: eDS Responsive Menu <= 1.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-68845 affects the Eds Responsive Menu plugin for WordPress (up to version 1.2) with a CVSS score of 6.1. It allows unauthenticated attackers to exploit reflected XSS. Ensure you update to the patched version to mitigate risks.
March 18, 2026

CVE-2025-68895: AhaChat Messenger Marketing <= 1.1 Authentication Bypass PoC, Patch Analysis & Rule

CVE-2025-68895 affects the AhaChat Messenger Marketing plugin for WordPress (up to v1.1) with a medium severity (CVSS 5.3) authentication bypass vulnerability. Users should update to the patched version to mitigate unauthorized access.
March 18, 2026

CVE-2025-68844: Membee Login <= 2.3.6 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-68844 affects the Membees Member Login Widget (up to 2.3.6) with a high severity CVSS score of 7.2. Patch to version 2.3.7 to mitigate the stored XSS vulnerability that could compromise site security.
March 18, 2026

CVE-2026-1056: Snow Monkey Forms <= 12.0.3 Unauthenticated Arbitrary File Deletion via Path Traversal PoC, Patch Analysis & Rule

CVE-2026-1056 affects the Snow Monkey Forms plugin for WordPress (up to 12.0.3) with a critical CVSS score of 9.8. Patch to version 12.0.4 to mitigate the risk of unauthenticated file deletion vulnerabilities.
March 18, 2026

CVE-2025-14316: AhaChat Messenger Marketing <= 1.1 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-14316 affects the AhaChat Messenger Marketing plugin (v1.1) with a high severity CVSS score of 7.2. Unauthenticated stored XSS allows script injection; ensure you patch to mitigate risks.
March 18, 2026

CVE-2025-67977: HAPPY <= 1.0.8 Missing Authorization PoC, Patch Analysis & Rule

CVE-2025-67977 affects the Happy Helpdesk Support Ticket System plugin (v1.0.8) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this missing capability check, so ensure you update to the patched version.
March 18, 2026

CVE-2026-1060: WP Adminify <= 4.0.7.7 Unauthenticated Sensitive Information Exposure via 'get-addons-list' REST API PoC, Patch Analysis & Rule

CVE-2026-1060 affects the Adminify plugin for WordPress, exposing sensitive information via an insecure REST API endpoint. Upgrade to version 4.0.7.8 to mitigate this medium-severity vulnerability.
March 18, 2026

CVE-2025-68855: JobBoard Job listing <= 1.2.8 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

CVE-2025-68855 affects the Job Board Light plugin (up to v1.2.8) with a medium severity score of 5.3. Unauthenticated attackers can access sensitive data, so ensure timely patching or consider WAF solutions.
March 18, 2026

CVE-2025-68843: FeedWordPress Advanced Filters <= 0.6.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-68843 affects the FeedWordPress Advanced Filters plugin (up to version 0.6.2) with a medium severity CVSS score of 6.1. Ensure you update to version 0.61 to mitigate the reflected cross-site scripting risk.
March 18, 2026

CVE-2025-68856: Mopinion Feedback Form <= 1.1.1 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-68856 affects the Mopinion Feedback Form plugin for WordPress (up to v1.1.1) with a medium severity CVSS score of 6.1. Unauthenticated attackers can exploit this reflected XSS vulnerability, highlighting the need for immediate...
March 18, 2026

CVE-2025-68847: iSape <= 0.72 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-68847 affects the iSape plugin for WordPress (up to version 0.72) with a medium severity CVSS score of 6.1. Users should patch to mitigate reflected XSS risks from insufficient input sanitization.
March 18, 2026

CVE-2025-14039: Simple Folio <= 1.1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'Client name' and 'Link' Meta Fields PoC, Patch Analysis & Rule

CVE-2025-14039 affects the Simple Folio plugin for WordPress (up to 1.1.1) with a medium severity CVSS of 6.4. Authenticated attackers can exploit this XSS vulnerability; update to version 1.1.2 to mitigate risks.
March 18, 2026

CVE-2026-1295: Buy Now Plus <= 1.0.2 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2026-1295 affects the Buy Now Plus plugin (up to v1.0.2) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should upgrade to v1.0.3 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026

CVE-2025-68531: ModelTheme Addons for WPBakery and Elementor < 1.5.6 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule

CVE-2025-68531 affects Modeltheme Addons for WPBakery versions up to 1.5.6, with a CVSS score of 7.5. Authenticated attackers can exploit a file upload vulnerability, risking data exposure and remote code execution. Patching is essential.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works