Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-1098: CM CSS Columns <= 1.2.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-1098 affects the CM CSS Columns plugin (up to 1.2.1) with a CVSS score of 6.4. This medium severity stored XSS vulnerability allows authenticated users to inject scripts. Users should update to the patched version to mitigate...
March 18, 2026

CVE-2025-14630: AdminQuickbar <= 1.9.3 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

CVE-2025-14630 affects the AdminQuickbar plugin for WordPress (up to version 1.9.3) with a medium severity CVSS score of 4.3. Patching is essential to mitigate potential unauthorized changes to settings and post titles.
March 18, 2026

CVE-2026-1088: Login Page Editor <= 1.2 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

CVE-2026-1088 affects the Login Page Editor plugin for WordPress (up to v1.2) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure you update to the patched version to prevent unauthorized changes to login settings.
March 18, 2026

CVE-2026-1095: Canto Testimonials <= 1.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'fx' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-1095 affects the Canto Testimonials plugin (v1.0) with a medium severity (CVSS 6.4) stored XSS vulnerability. Authenticated attackers can inject scripts, impacting user security. Ensure you update to the patched version.
March 18, 2026

CVE-2025-13676: JustClick registration plugin <= 0.1 Reflected Cross-Site Scripting via PHP_SELF PoC, Patch Analysis & Rule

CVE-2025-13676 affects the JustClick Subscriber plugin (version 0.1) with a medium severity CVSS score of 6.1. Users should update to the patched version to mitigate the risk of reflected cross-site scripting attacks.
March 18, 2026

CVE-2026-0806: WP-ClanWars <= 2.0.1 Authenticated (Administrator+) SQL Injection via 'orderby' Parameter PoC, Patch Analysis & Rule

CVE-2026-0806 affects the WP-ClanWars plugin (up to version 2.0.1) with a medium severity SQL injection vulnerability. Admin-level attackers can exploit this flaw to execute arbitrary SQL commands, highlighting the need for immediate...
March 18, 2026

CVE-2025-14843: Wizit Gateway for WooCommerce <= 1.2.9 Missing Authentication to Unauthenticated Arbitrary Order Cancellation PoC, Patch Analysis & Rule

CVE-2025-14843 affects the Wizit Gateway for WooCommerce plugin (up to v1.2.9) with a medium severity (CVSS 5.3) remote code execution vulnerability. Update to v1.3.0 to mitigate unauthorized order cancellations.
March 18, 2026

CVE-2026-1097: ThemeRuby Multi Authors <= 1.0.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2026-1097 affects the ThemeRuby Multi Authors plugin (v1.0.0) with a CVSS score of 6.4. This medium-severity XSS vulnerability allows authenticated users to inject scripts. Ensure you update to the patched version to mitigate risks.
March 18, 2026

CVE-2025-14941: GZSEO <= 2.0.11 Authenticated (Contributor+) Authorization Bypass to Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-14941 affects the Gzseo plugin for WordPress (up to version 2.0.11) with a medium severity (CVSS 6.4) XSS vulnerability. Users should update to version 2.0.12 to mitigate the risk of unauthorized script injection.
March 18, 2026

CVE-2026-1081: Set Bulk Post Categories <= 1.1 Cross-Site Request Forgery to Bulk Post Category Update PoC, Patch Analysis & Rule

CVE-2026-1081 affects the Set Bulk Post Categories plugin (v1.1) with a medium severity score of 4.3. Ensure to patch against this cross-site request forgery vulnerability to prevent unauthorized bulk category changes.
March 18, 2026

CVE-2026-1070: Alex User Counter <= 6.0 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

CVE-2026-1070 affects the User Counter plugin for WordPress (up to version 6.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Patching is essential to prevent unauthorized changes by tricking admins into clicking malicious links.
March 18, 2026

CVE-2025-14985: Alpha Blocks <= 1.5.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'alpha_block_css' Post Meta PoC, Patch Analysis & Rule

CVE-2025-14985 affects the Alpha Blocks plugin (up to v1.5.0) with a medium severity CVSS score of 6.4. Authenticated users can exploit a stored XSS vulnerability. Ensure timely patching to protect your site.
March 18, 2026

CVE-2026-1076: Star Review Manager <= 1.2.2 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

CVE-2026-1076 affects the Star Review Manager plugin (up to v1.2.2) with a Medium severity (CVSS 4.3) CSRF vulnerability. Ensure you update to the patched version to mitigate unauthorized CSS changes.
March 18, 2026

CVE-2026-1099: Administrative Shortcodes <= 0.3.4 Authenticated (Contributor+) Stored Cross-Site Scripting via 'login' and 'logout' Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2026-1099 affects the Administrative Shortcodes plugin for WordPress (up to version 0.3.4) with a medium severity CVSS of 6.4. Authenticated attackers can exploit this stored XSS vulnerability, so patching is essential.
March 18, 2026

CVE-2026-1257: Administrative Shortcodes <= 0.3.4 Authenticated (Contributor+) Local File Inclusion via 'slug' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-1257 affects the Administrative Shortcodes plugin (up to 0.3.4) with a high severity (CVSS 7.5) Local File Inclusion vulnerability. Patch immediately to prevent authenticated attackers from executing arbitrary PHP code.
March 18, 2026

CVE-2026-1075: ZT Captcha <= 1.0.4 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

CVE-2026-1075 affects the ZT Captcha plugin for WordPress (up to 1.0.4) with a medium severity (CVSS 4.3) CSRF vulnerability. Admins should patch to prevent unauthorized settings changes via malicious links.
March 18, 2026

CVE-2026-1103: AIKTP <= 5.0.04 Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions PoC, Patch Analysis & Rule

CVE-2026-1103 affects the Aiktp plugin (up to version 5.0.04) with a medium severity (CVSS 5.4) vulnerability. Ensure you update to version 5.0.5 to mitigate unauthorized access to admin tokens.
March 18, 2026

CVE-2026-1084: Cookie consent for developers <= 1.7.1 Authenticated (Administrator+) Stored Cross-Site Scripting via Multiple Settings Fields PoC, Patch Analysis & Rule

CVE-2026-1084 affects the Cookie Consent For Developers plugin for WordPress (up to v1.7.1) with a medium severity CVSS of 4.4. Authenticated admins can exploit stored XSS vulnerabilities, so patching is crucial.
March 18, 2026

CVE-2026-0807: Frontis Blocks <= 1.1.6 Unauthenticated Server-Side Request Forgery via 'url' Parameter PoC, Patch Analysis & Rule

CVE-2026-0807 affects the Frontis Blocks plugin (up to 1.1.6) with a high severity CVSS score of 7.2 due to SSRF vulnerabilities. Update to version 1.1.7 to mitigate potential unauthorized web requests.
March 18, 2026

CVE-2025-14609: Wise Analytics <= 1.1.9 Missing Authorization to Unauthenticated Arbitrary Analytics Database Disclosure via 'name' Parameter PoC, Patch Analysis & Rule

CVE-2025-14609 affects the Wise Analytics plugin (up to version 1.1.9) with a medium severity score of 5.3. Unauthenticated attackers can access sensitive data via the REST API. Update to version 1.1.20 to mitigate this risk.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works