
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-24390: Kentha Elementor Widgets < 3.1 Authenticated (Contributor+) Local File Inclusion PoC, Patch Analysis & Rule
CVE-2026-24390 affects the Kentha Elementor plugin (up to version 3.1) with a CVSS score of 7.5. It allows authenticated users to bypass access controls and execute arbitrary PHP code. Patching is essential to mitigate this risk.
March 18, 2026
CVE-2026-24541: Download After Email <= 2.1.9 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-24541 affects the Download After Email plugin (up to 2.1.9) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Users should update to the patched version to mitigate risks.
March 18, 2026
CVE-2026-24539: Protección de datos – RGPD <= 0.68 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-24539 affects the Protección de datos – RGPD plugin for WordPress versions up to 0.68, allowing unauthorized access. Update to version 0.69 to mitigate this medium severity vulnerability.
March 18, 2026
CVE-2026-0911: Hustle <= 7.8.9.2 Authenticated (Subscriber+) Arbitrary File Upoload via Module Import PoC, Patch Analysis & Rule
CVE-2026-0911 affects the WordPress Popup plugin (up to version 7.8.9.2) with a CVSS score of 7.5. This high-severity file upload vulnerability allows authenticated users to upload arbitrary files, risking remote code execution. Update...
March 18, 2026
CVE-2025-13205: SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 2.5.2 Cross-Site Request Forgery to Survey Cloning PoC, Patch Analysis & Rule
CVE-2025-13205 affects the SurveyJS plugin (up to v2.5.2) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure you update to the patched version to prevent unauthorized survey duplication.
March 18, 2026
CVE-2025-13920: WP Directory Kit <= 1.4.9 Unauthenticated Email Exposure via wdk_public_action PoC, Patch Analysis & Rule
CVE-2025-13920 affects the WP Directory Kit plugin (up to v1.4.9) with a CVSS score of 5.3, exposing user emails via an AJAX handler. Upgrade to v1.5.0 to mitigate this sensitive information exposure.
March 18, 2026
CVE-2026-1300: Responsive Header Plugin <= 1.0 Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters PoC, Patch Analysis & Rule
CVE-2026-1300 affects the Responsive Header plugin for WordPress (v1.0 and below) with a medium severity (CVSS 4.4) stored XSS vulnerability. Admins should patch to prevent script injection on affected sites.
March 18, 2026
CVE-2025-13139: SurveyJS: Drag & Drop WordPress Form Builder <= 2.5.2 Cross-Site Request Forgery to Survey Creation PoC, Patch Analysis & Rule
CVE-2025-13139 affects the SurveyJS plugin (up to v2.5.2) with a CVSS score of 4.3. This medium severity CSRF vulnerability allows attackers to create surveys by tricking admins into clicking malicious links. Patching is essential.
March 18, 2026
CVE-2025-13194: SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 2.5.2 Cross-Site Request Forgery to Survey Renaming PoC, Patch Analysis & Rule
CVE-2025-13194 affects the SurveyJS plugin (up to version 2.5.2) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure to update to the patched version to prevent unauthorized survey renaming.
March 18, 2026
CVE-2026-1208: Friendly Functions for Welcart <= 1.2.5 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule
CVE-2026-1208 affects the Friendly Functions For Welcart plugin (up to 1.2.5) with a medium severity CVSS score of 4.3. Update to version 1.2.6 to mitigate the Cross-Site Request Forgery risk.
March 18, 2026
CVE-2026-1127: Timeline Event History <= 3.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-1127 affects the Timeline Event History plugin for WordPress (up to version 3.2) with a medium severity CVSS score of 6.1. Ensure to patch against this reflected XSS vulnerability to protect users from potential script injection.
March 18, 2026
CVE-2026-1189: LeadBI Plugin for WordPress <= 1.7 Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_id' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1189 affects the Leadbi plugin for WordPress (up to v1.7) with a medium severity (CVSS 6.4) stored XSS vulnerability. Authenticated users can inject scripts, so patching is essential to secure your site.
March 18, 2026
CVE-2026-1266: Postalicious <= 3.0.1 Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings PoC, Patch Analysis & Rule
CVE-2026-1266 affects the Postalicious plugin for WordPress (up to 3.0.1) with a CVSS score of 4.4. Admin-level attackers can exploit this stored XSS vulnerability, so ensure you patch to the latest version to mitigate risks.
March 18, 2026
CVE-2026-0800: User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20251210 Unauthenticated Stored Cross-Site Scripting via Custom Field PoC, Patch Analysis & Rule
CVE-2026-0800 affects the User Submitted Posts plugin for WordPress, with a CVSS score of 7.2. Users should upgrade to version 20260110 to mitigate the high-severity stored XSS vulnerability.
March 18, 2026
CVE-2025-14907: Moderate Selected Posts <= 1.4 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule
CVE-2025-14907 affects the Moderate Selected Posts plugin for WordPress (up to v1.4) with a CVSS score of 4.3. Unauthenticated attackers can exploit this CSRF vulnerability to modify settings if an admin is tricked into clicking a link.
March 18, 2026
CVE-2026-1191: JavaScript Notifier <= 1.2.8 Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings PoC, Patch Analysis & Rule
CVE-2026-1191 affects the Javascript Notifier plugin (up to v1.2.8) with a medium severity (CVSS 4.4) stored XSS vulnerability. Admins should patch to prevent script injection risks on user-accessed pages.
March 18, 2026
CVE-2026-0687: Meta-box GalleryMeta <= 3.0.1 Missing Authorization to Authenticated (Author+) Gallery Management PoC, Patch Analysis & Rule
CVE-2026-0687 affects the Meta Box GalleryMeta plugin (up to version 3.0.1) with a medium severity CVSS score of 4.3. Authenticated users can exploit this to modify data; update to version 3.1 to mitigate.
March 18, 2026
CVE-2026-0633: MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 Unauthenticated Form Submission Exposure via Forgeable Cookie Value PoC, Patch Analysis & Rule
CVE-2026-0633 affects the Metform plugin (up to v4.1.0) with a CVSS score of 3.7, allowing unauthenticated access to sensitive form data. Update to v4.1.1 to mitigate this vulnerability.
March 18, 2026
CVE-2026-1302: Meta-box GalleryMeta <= 3.0.1 Authenticated (Editor+) Stored Cross-Site Scripting via Image Caption PoC, Patch Analysis & Rule
CVE-2026-1302 affects the Meta Box Gallerymeta plugin (up to v3.0.1) with a medium severity (CVSS 4.4) XSS vulnerability. Patch to v3.1 to mitigate risks from authenticated attackers in multi-site setups.
March 18, 2026
CVE-2025-15516: All-in-One Video Gallery 4.1.0 4.6.4 Missing Authorization to Authenticated (Subscriber+) Limited User Meta Update PoC, Patch Analysis & Rule
CVE-2025-15516 affects the All In One Video Gallery plugin (versions 4.1.0 to 4.6.4) with a CVSS score of 4.3. It allows authenticated users to modify user meta data. Update to version 4.7.1 to mitigate this risk.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
