Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-25010: Share This Image <= 2.09 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-25010 affects the Share This Image plugin (up to version 2.09) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this flaw, so update to version 2.10 to mitigate risks.
March 18, 2026

CVE-2026-24536: Webpushr <= 4.38.0 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

CVE-2026-24536 affects the Webpushr Web Push Notifications plugin (up to version 4.38.0) with a medium severity CVSS score of 5.3. Unauthenticated attackers can access sensitive data, so ensure you update to the patched version.
March 18, 2026

CVE-2026-24998: Hustle <= 7.8.9.2 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

CVE-2026-24998 affects the WordPress Popup plugin (up to version 7.8.9.2) with a medium severity score of 5.3, allowing unauthenticated attackers to expose sensitive data. Update to version 7.8.9.3 to mitigate this risk.
March 18, 2026

CVE-2026-25432: Omnipress <= 1.6.7 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-25432 affects the Omnipress WordPress plugin (up to version 1.6.7) with a medium severity CVSS score of 6.4. Authenticated users can exploit this stored XSS vulnerability, necessitating immediate patching to secure affected sites.
March 18, 2026

CVE-2026-24534: Booter <= 1.5.7 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24534 affects the Booter Bots Crawlers Manager plugin (up to v1.5.7) with a medium severity CVSS score of 4.3. Update to v1.5.8 to mitigate unauthorized access risks from authenticated users.
March 18, 2026

CVE-2026-24532: SiteLock Security <= 5.0.2 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24532 affects the SiteLock Security plugin for WordPress (up to version 5.0.2) with a medium severity (CVSS 4.3). Patch to version 5.0.3 to prevent unauthorized actions by authenticated users.
March 18, 2026

CVE-2025-6461: CubeWP – All-in-One Dynamic Content Framework <= 1.1.27 Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.php PoC, Patch Analysis & Rule

CVE-2025-6461 affects the CubeWP Framework plugin (up to v1.1.27) with a medium severity (CVSS 4.3) vulnerability. Unauthenticated attackers can access restricted posts; update to v1.1.28 to mitigate this risk.
March 18, 2026

CVE-2026-24535: Automatic Featured Images from Videos <= 1.2.7 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24535 affects the Automatic Featured Images From Videos plugin (up to v1.2.7) with a medium severity score of 4.3. Users should update to v1.2.8 to mitigate unauthorized access risks.
March 18, 2026

CVE-2026-0593: WP Go Maps (formerly WP Google Maps) <= 10.0.04 Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification PoC, Patch Analysis & Rule

CVE-2026-0593 affects the WP Google Maps plugin versions up to 10.0.04, allowing authenticated users to modify map settings. Update to version 10.0.05 to mitigate this medium severity vulnerability.
March 18, 2026

CVE-2026-25012: Bannerize Pro <= 1.11.0 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-25012 affects WP Bannerize Pro versions up to 1.11.0, allowing unauthorized access to sensitive content. Upgrade to 1.11.1 to mitigate this medium severity vulnerability with a CVSS score of 5.3.
March 18, 2026

CVE-2026-24996: WPElemento Importer <= 0.6.4 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24996 affects the WPElemento Importer plugin (up to v0.6.4) with a medium severity CVSS score of 4.3. Patch to v0.6.5 to mitigate unauthorized access risks from authenticated attackers.
March 18, 2026

CVE-2026-0862: Save as PDF Plugin by PDFCrowd <= 4.5.5 Reflected Cross-Site Scripting via options PoC, Patch Analysis & Rule

CVE-2026-0862 affects the Save As Pdf By Pdfcrowd plugin for WordPress (up to version 4.5.5) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Users should update to the patched version to mitigate risks.
March 18, 2026

CVE-2026-24543: Materialis Companion <= 1.3.52 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24543 affects the Materialis Companion plugin for WordPress (up to 1.3.52) with a medium severity (CVSS 4.3). Authenticated users can exploit a missing capability check, so update to the patched version to mitigate risks.
March 18, 2026

CVE-2026-24538: Omnipress <= 1.6.7 Authenticated (Contributor+) Local File Inclusion PoC, Patch Analysis & Rule

CVE-2026-24538 affects the Omnipress plugin for WordPress (up to v1.6.7) with a high severity (CVSS 7.5) authentication bypass vulnerability. Patching is crucial to prevent unauthorized file execution and data exposure.
March 18, 2026

CVE-2026-24379: Job Portal <= 2.4.3 Authenticated (Subscriber+) Insecure Direct Object Reference PoC, Patch Analysis & Rule

CVE-2026-24379 affects the WP Job Portal plugin (up to v2.4.3) with a medium severity CVSS score of 4.3. Authenticated users can exploit this IDOR vulnerability, so update to v2.4.4 to mitigate risks.
March 18, 2026

CVE-2026-24540: Integrate Google Drive <= 1.5.6 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24540 affects the Integrate Google Drive plugin (up to v1.5.6) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized actions by authenticated users. Update to the patched version to mitigate risks.
March 18, 2026

CVE-2026-24544: HD Quiz <= 2.0.9 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24544 affects the HD Quiz plugin (up to version 2.0.9) with a medium severity CVSS score of 4.3. Authenticated users can exploit a missing capability check, so update to version 2.0.10 to mitigate this risk.
March 18, 2026

CVE-2026-24542: Term Order <= 2.1.0 Cross-Site Request Forgery PoC, Patch Analysis & Rule

CVE-2026-24542 affects the Wp Term Order plugin (up to version 2.1.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure to update to the patched version to mitigate unauthorized actions via forged requests.
March 18, 2026

CVE-2026-24997: Wired Impact Volunteer Management <= 2.8 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24997 affects the Wired Impact Volunteer Management plugin for WordPress (versions up to 2.8) with a medium severity (CVSS 5.3) vulnerability. Patch to 2.8.1 to prevent unauthorized access to user data.
March 18, 2026

CVE-2026-24995: Latest Post Shortcode <= 14.2.0 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24995 affects the Latest Post Shortcode plugin (up to v14.2.0) with a medium severity score of 4.3. Ensure you update to v14.2.1 to mitigate unauthorized access risks from authenticated users.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works