
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1404: Ultimate Member <= 2.11.1 Reflected Cross-Site Scripting via Filter Parameters PoC, Patch Analysis & Rule
Medium CVE-2026-1404 in Ultimate Member (CVSS 6.1): Ultimate Member. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.11.2.
March 18, 2026
CVE-2026-1317: WP Import – Ultimate CSV XML Importer for WordPress <= 7.37 Authenticated (Subscriber+) SQL Injection via File Name PoC, Patch Analysis & Rule
Medium CVE-2026-1317 in Wp Ultimate Csv Importer (CVSS 6.5): WP Import – Ultimate CSV XML Importer for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 7.38.
March 18, 2026
CVE-2026-0829: Frontend File Manager <= 23.5 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-0829 in Nmedia User File Uploader (CVSS 5.3): Frontend File Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 23.6.
March 18, 2026
CVE-2026-22384: Applay Shortcodes <= 3.7 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-22384 in Applay Shortcodes (CVSS 7.5): Applay - Shortcodes. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1216: RSS Aggregator <= 5.0.10 Reflected Cross-Site Scripting via 'template' Parameter PoC, Patch Analysis & Rule
High CVE-2026-1216 in Wp Rss Aggregator (CVSS 7.2): RSS Aggregator. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.0.11.
March 18, 2026
CVE-2026-1582: WP All Export <= 1.4.14 Unauthenticated Sensitive Information Exposure via PHP Type Juggling PoC, Patch Analysis & Rule
Low CVE-2026-1582 in Wp All Export (CVSS 3.7): WP All Export. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.4.15.
March 18, 2026
CVE-2026-1657: EventPrime <= 4.2.8.4 Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint PoC, Patch Analysis & Rule
Medium CVE-2026-1657 in Eventprime Event Calendar Management (CVSS 5.3): EventPrime. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.2.8.5.
March 18, 2026
CVE-2026-2592: Zarinpal Gateway for WooCommerce <= 5.0.16 Improper Access Control to Payment Status Update PoC, Patch Analysis & Rule
High CVE-2026-2592 in Zarinpal Woocommerce Payment Gateway (CVSS 7.7): Zarinpal Gateway for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.0.17.
March 18, 2026
CVE-2026-1426: Advanced AJAX Product Filters <= 3.1.9.6 Authenticated (Author+) PHP Object Injection via Live Composer Compatibility PoC, Patch Analysis & Rule
High CVE-2026-1426 in Woocommerce Ajax Filters (CVSS 8.8): Advanced AJAX Product Filters. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.1.9.7.
March 18, 2026
CVE-2025-69337: Wolmart Core <= 1.9.6 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
High CVE-2025-69337 in Wolmart Core (CVSS 7.5): Wolmart Core. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-2002: Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.50.2 Authenticated (Administrator+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-2002 in Forminator (CVSS 4.4): Forminator Forms – Contact Form, Payment Form & Custom Form Builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-12062: WP Maps <= 4.8.6 Authenticated (Subscriber+) Limited Local File Inclusion PoC, Patch Analysis & Rule
High CVE-2025-12062 in Wp Google Map Plugin (CVSS 8.8): WP Maps. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.8.7.
March 18, 2026
CVE-2026-2001: WowRevenue <= 2.1.3 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation PoC, Patch Analysis & Rule
High CVE-2026-2001 in Revenue (CVSS 8.8): WowRevenue. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.4.
March 18, 2026
CVE-2025-8781: Bookster – WordPress Appointment Booking Plugin <= 2.1.1 Authenticated (Administrator+) SQL Injection via 'raw' PoC, Patch Analysis & Rule
Medium CVE-2025-8781 in Bookster (CVSS 4.9): Bookster – WordPress Appointment Booking Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.2.0.
March 18, 2026
CVE-2025-68002: Open User Map <= 1.4.16 Authenticated (Subscriber+) Arbitrary File Download PoC, Patch Analysis & Rule
Medium CVE-2025-68002 in Open User Map (CVSS 6.5): Open User Map. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.4.17.
March 18, 2026
CVE-2026-22354: Woocommerce Category Banner Management <= 2.5.1 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-22354 in Banner Management For Woocommerce (CVSS 7.5): Woocommerce Category Banner Management. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-25363: FooGallery <= 3.1.11 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-25363 in Foogallery (CVSS 4.3): FooGallery. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.1.13.
March 18, 2026
CVE-2026-25368: Calculated Fields Form <= 5.4.4.1 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-25368 in Calculated Fields Form (CVSS 4.3): Calculated Fields Form. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.4.4.2.
March 18, 2026
CVE-2026-22357: Link Whisper Free <= 0.9.0 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-22357 in Link Whisper (CVSS 6.1): Link Whisper Free. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 0.9.1.
March 18, 2026
CVE-2026-1793: Element Pack Addons for Elementor <= 8.3.17 Authenticated (Contributor+) Arbitrary File Read PoC, Patch Analysis & Rule
Medium CVE-2026-1793 in Bdthemes Element Pack Lite (CVSS 6.5): Element Pack Addons for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 8.3.18.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
