Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2025-14906: WP Youtube Video Gallery <= 1.0 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule

CVE-2025-14906 affects the WP Youtube Video Gallery plugin (version 1.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure you update to the patched version to prevent unauthorized settings changes.
March 18, 2026

CVE-2025-14797: Same Category Posts <= 1.1.19 Authenticated (Author+) Stored Cross-Site Scripting via Widget Title Placeholder PoC, Patch Analysis & Rule

CVE-2025-14797 affects the Same Category Posts plugin (up to v1.1.19) with a medium severity CVSS score of 5.4. Patch to v1.1.20 to mitigate stored XSS risks from authenticated users injecting scripts.
March 18, 2026

CVE-2025-14903: Simple Crypto Shortcodes <= 1.0.2 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule

CVE-2025-14903 affects the Simple Crypto Shortcodes plugin (v1.0.2) with a CVSS score of 4.3. It allows unauthenticated attackers to exploit CSRF vulnerabilities, making it essential to patch or implement WAF coverage.
March 18, 2026

CVE-2025-13374: Kalrav AI Agent <= 2.3.3 Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action PoC, Patch Analysis & Rule

CVE-2025-13374 affects the Kalrav AI Agent plugin (v2.3.3) with a critical CVSS score of 9.8. Unauthenticated file uploads can lead to remote code execution. Users should patch to the latest version to mitigate this risk.
March 18, 2026

CVE-2025-14629: Alchemist Ajax Upload <= 1.1 Missing Authorization to Unauthenticated Arbitrary Media File Deletion PoC, Patch Analysis & Rule

CVE-2025-14629 affects the Alchemist Ajax Upload plugin (up to v1.1) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized deletion of media files. Users should patch to the latest version to mitigate this risk.
March 18, 2026

CVE-2026-24994: Sunshine Photo Cart <= 3.5.7.2 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-24994 affects Sunshine Photo Cart plugin versions up to 3.5.7.2, allowing unauthorized access to sensitive image metadata. Upgrade to 3.5.7.3 to mitigate this medium severity vulnerability with a CVSS score of 5.3.
March 18, 2026

CVE-2026-24991: Extensions For CF7 <= 3.4.0 Authenticated (Contributor+) Insecure Direct Object Reference PoC, Patch Analysis & Rule

CVE-2026-24991 affects the Extensions For CF7 plugin for WordPress (up to version 3.4.0) with a medium severity (CVSS 4.3) IDOR vulnerability. Users should update to version 3.4.1 to mitigate unauthorized access risks.
March 18, 2026

CVE-2025-68848: amr cron manager <= 2.3 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-68848 affects the Amr Cron Manager plugin for WordPress (up to version 2.3) with a high severity CVSS score of 7.2. This stored XSS vulnerability allows unauthenticated attackers to inject scripts, necessitating immediate patching.
March 18, 2026

CVE-2025-12836: VK Google Job Posting Manager <= 1.2.23 Authenticated (Author+) Stored Cross-Site Scripting via Job Description Field PoC, Patch Analysis & Rule

CVE-2025-12836 affects the VK Google Job Posting Manager plugin (up to version 1.2.23) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should upgrade to version 1.2.24 to mitigate the risk of script injection.
March 18, 2026

CVE-2025-68999: Happy Addons for Elementor <= 3.20.4 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule

CVE-2025-68999 affects the Happy Elementor Addons plugin (up to version 3.20.4) with a medium severity SQL injection vulnerability. Users should update to version 3.20.6 to mitigate risks of unauthorized database access.
March 18, 2026

CVE-2026-24548: Radio Player <= 2.0.91 Unauthenticated Server-Side Request Forgery PoC, Patch Analysis & Rule

CVE-2026-24548 affects the Radio Player plugin for WordPress (up to 2.0.91) with a CVSS score of 7.2. This high-severity Server-Side Request Forgery vulnerability allows unauthenticated attackers to make arbitrary web requests. Patching...
March 18, 2026

CVE-2026-1251: SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 Authenticated (Subscriber+) Insecure Direct Object Reference PoC, Patch Analysis & Rule

CVE-2026-1251 affects the SupportCandy plugin (up to v3.4.4) with a CVSS score of 5.4. Authenticated users can exploit this medium-severity vulnerability to access others' file attachments. Upgrade to v3.4.5 to mitigate risks.
March 18, 2026

CVE-2026-1720: WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation <= 1.4.24 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation PoC, Patch Analysis & Rule

CVE-2026-1720 affects the Optin plugin (v1.4.24) with a high severity CVSS score of 8.8. Authenticated attackers can exploit this to install arbitrary plugins. Update to v1.4.25 to mitigate this risk.
March 18, 2026

CVE-2026-24963: Booking for Appointments and Events Calendar – Amelia <= 1.2.38 Authenticated (Employee+) Privilege Escalation PoC, Patch Analysis & Rule

CVE-2026-24963 affects the AmeliaBooking plugin (up to v1.2.38) with a high severity CVSS score of 8.8. Authenticated users can escalate privileges to admin. Update to v2.0 to mitigate this vulnerability.
March 18, 2026

CVE-2026-3058: Seraphinite Accelerator <= 2.28.14 Authenticated (Subscriber+) Exposure of Sensitive Information to an Unauthorized Actor PoC, Patch Analysis & Rule

CVE-2026-3058 affects the Seraphinite Accelerator plugin (up to v2.28.14) with a CVSS score of 4.3. Authenticated users can access sensitive data. Update to v2.28.15 to mitigate this vulnerability.
March 18, 2026

CVE-2026-2355: My Calendar – Accessible Event Manager <= 3.7.3 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2026-2355 affects the My Calendar plugin (up to version 3.7.3) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should update to the patched version to mitigate the risk of script injection.
March 18, 2026

CVE-2026-22479: Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress <= 2.2.0 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-22479 affects the Easy Post Submission plugin (up to v2.2.0) with a CVSS score of 5.3. It allows unauthorized access due to a missing capability check. Update to v2.3.0 to mitigate this risk.
March 18, 2026

CVE-2026-3056: Seraphinite Accelerator <= 2.28.14 Missing Authorization to Authenticated (Subscriber+) Log Clearing PoC, Patch Analysis & Rule

CVE-2026-3056 affects the Seraphinite Accelerator plugin (up to version 2.28.14) with a medium severity (CVSS 4.3) vulnerability. Update to version 2.28.15 to prevent unauthorized log modifications by authenticated users.
March 18, 2026

CVE-2026-1706: All-in-One Video Gallery <= 4.7.1 Reflected Cross-Site Scripting via 'vi' Parameter PoC, Patch Analysis & Rule

CVE-2026-1706 affects the All In One Video Gallery plugin for WordPress (up to version 4.7.1) with a medium severity score of 6.1. Users should update to version 4.7.5 to mitigate the reflected XSS vulnerability.
March 18, 2026

CVE-2023-7337: JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 Unauthenticated SQL Injection via ‘js-support-ticket-token-tkstatus’ Cookie PoC, Patch Analysis & Rule

CVE-2023-7337 affects the Js Support Ticket plugin (v2.8.2) with a high severity score of 7.5 due to SQL injection risks. Users should upgrade to version 2.8.3 to mitigate potential data exposure.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works