Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2025-69305: Crete Core <= 1.4.3 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2025-69305 affects the Crete Core WordPress plugin (up to version 1.4.3) with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated attackers to extract sensitive database information. Patching...
March 18, 2026

CVE-2026-0702: VidShop – Shoppable Videos for WooCommerce <= 1.1.4 Unauthenticated Time-Based SQL Injection via 'fields' PoC, Patch Analysis & Rule

CVE-2026-0702 affects the Vidshop For WooCommerce plugin (up to version 1.1.4) with a high severity SQL injection vulnerability (CVSS 7.5). Update to version 1.1.5 to mitigate the risk of data extraction by attackers.
March 18, 2026

CVE-2025-68031: افزونه پیامک حرفه ای فراز اس ام اس <= 2.7.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-68031 affects the Farazsms plugin for WordPress (up to version 2.7.3) with a CVSS score of 6.1. Users should patch to mitigate the reflected XSS vulnerability that allows attackers to inject scripts.
March 18, 2026

CVE-2025-68050: Leadpages <= 1.1.3 Missing Authorization PoC, Patch Analysis & Rule

CVE-2025-68050 affects the Leadpages plugin for WordPress (up to version 1.1.3) with a medium severity score of 5.3. Ensure to update to version 1.1.4 to mitigate unauthorized access risks.
March 18, 2026

CVE-2025-68846: Asynchronous Javascript <= 1.3.5 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-68846 affects the Asynchronous Javascript plugin for WordPress (up to version 1.3.5) with a medium severity CVSS of 6.1. Users should patch to mitigate the risk of reflected XSS attacks.
March 18, 2026

CVE-2025-67972: Prague <= 2.2.8 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-67972 reveals a high severity XSS vulnerability in the Prague Plugins for WordPress (up to version 2.2.8). Unauthenticated attackers can inject scripts, impacting user security. Ensure to update to the patched version.
March 18, 2026

CVE-2025-14971: Link Invoice Payment for WooCommerce <= 2.8.0 Missing Authorization to Unauthenticated Arbitrary Partial Payment Creation/Cancellation PoC, Patch Analysis & Rule

CVE-2025-14971 affects the Invoice Payment For WooCommerce plugin (up to v2.8.0) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized partial payment modifications. Update to v2.8.1 to mitigate this risk.
March 18, 2026

CVE-2026-24523: FullCalendar <= 1.6 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

CVE-2026-24523 affects the WP FullCalendar plugin (up to v1.6) with a CVSS score of 5.3. Unauthenticated attackers can access sensitive data, highlighting the need for immediate patching.
March 18, 2026

CVE-2026-24389: Gallery PhotoBlocks <= 1.3.2 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-24389 affects the Photoblocks Grid Gallery plugin (up to v1.3.2) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should upgrade to v1.3.3 to mitigate risks from potential script injections.
March 18, 2026

CVE-2026-24522: Subscribe <= 1.2.16 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24522 affects the Wp Subscribe plugin (versions
March 18, 2026

CVE-2026-24528: Nova Blocks <= 2.1.9 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-24528 affects the Nova Blocks plugin for WordPress (up to version 2.1.9) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability, making timely patching essential.
March 18, 2026

CVE-2026-24524: Tablesome <= 1.2.2 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24524 affects the Tablesome plugin for WordPress (up to version 1.2.2) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized actions by authenticated users. Update to version 1.2.4 to mitigate risks.
March 18, 2026

CVE-2026-24526: Email Inquiry & Cart Options for WooCommerce <= 3.4.3 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-24526 affects the WooCommerce Email Inquiry Cart Options plugin (up to v3.4.3) with a CVSS score of 6.4. It allows authenticated attackers to inject scripts, impacting user security. Patching is essential.
March 18, 2026

CVE-2026-24377: Nexter Blocks <= 4.6.3 Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule

CVE-2026-24377 affects The Plus Addons For Block Editor plugin (up to version 4.6.3) with a CVSS score of 4.3. Authenticated attackers can expose sensitive data, so update to version 4.6.4 to mitigate risks.
March 18, 2026

CVE-2026-24525: CLP Varnish Cache <= 1.0.2 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24525 affects the CLP Varnish Cache plugin (up to 1.0.2) with a medium severity CVSS score of 5.3. Unauthenticated attackers can trigger cache purges, impacting site performance. Upgrade to version 1.0.3 to mitigate.
March 18, 2026

CVE-2026-24529: Quick Restaurant Reservations <= 1.6.7 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24529 affects the Quick Restaurant Reservations plugin (up to 1.6.7) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this flaw, so ensure you update to the patched version for security.
March 18, 2026

CVE-2026-24521: Kama Thumbnail <= 3.5.1 Cross-Site Request Forgery PoC, Patch Analysis & Rule

CVE-2026-24521 affects the Kama Thumbnail plugin (up to version 3.5.1) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure you update to the patched version to mitigate unauthorized actions.
March 18, 2026

CVE-2026-24530: WebP Conversion <= 2.1 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24530 affects the WebP Conversion plugin for WordPress versions up to 2.1, allowing unauthorized access due to a missing capability check. Upgrade to version 2.2 to mitigate this medium severity vulnerability.
March 18, 2026

CVE-2026-25011: Custom Admin Interface <= 7.41 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-25011 affects the WP Custom Admin Interface plugin (up to version 7.41) with a CVSS score of 4.3. Ensure you update to version 7.42 to mitigate unauthorized access risks.
March 18, 2026

CVE-2025-67970: Schedula <= 1.0 Missing Authorization PoC, Patch Analysis & Rule

CVE-2025-67970 affects the Schedula Smart Appointment Booking plugin for WordPress (v1.0). With a CVSS score of 5.3, it allows unauthorized access. Users should patch to mitigate risks.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works