
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2025-14906: WP Youtube Video Gallery <= 1.0 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule
CVE-2025-14906 affects the WP Youtube Video Gallery plugin (version 1.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure you update to the patched version to prevent unauthorized settings changes.
March 18, 2026
CVE-2025-14797: Same Category Posts <= 1.1.19 Authenticated (Author+) Stored Cross-Site Scripting via Widget Title Placeholder PoC, Patch Analysis & Rule
CVE-2025-14797 affects the Same Category Posts plugin (up to v1.1.19) with a medium severity CVSS score of 5.4. Patch to v1.1.20 to mitigate stored XSS risks from authenticated users injecting scripts.
March 18, 2026
CVE-2025-14903: Simple Crypto Shortcodes <= 1.0.2 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule
CVE-2025-14903 affects the Simple Crypto Shortcodes plugin (v1.0.2) with a CVSS score of 4.3. It allows unauthenticated attackers to exploit CSRF vulnerabilities, making it essential to patch or implement WAF coverage.
March 18, 2026
CVE-2025-13374: Kalrav AI Agent <= 2.3.3 Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action PoC, Patch Analysis & Rule
CVE-2025-13374 affects the Kalrav AI Agent plugin (v2.3.3) with a critical CVSS score of 9.8. Unauthenticated file uploads can lead to remote code execution. Users should patch to the latest version to mitigate this risk.
March 18, 2026
CVE-2025-14629: Alchemist Ajax Upload <= 1.1 Missing Authorization to Unauthenticated Arbitrary Media File Deletion PoC, Patch Analysis & Rule
CVE-2025-14629 affects the Alchemist Ajax Upload plugin (up to v1.1) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized deletion of media files. Users should patch to the latest version to mitigate this risk.
March 18, 2026
CVE-2026-24994: Sunshine Photo Cart <= 3.5.7.2 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-24994 affects Sunshine Photo Cart plugin versions up to 3.5.7.2, allowing unauthorized access to sensitive image metadata. Upgrade to 3.5.7.3 to mitigate this medium severity vulnerability with a CVSS score of 5.3.
March 18, 2026
CVE-2026-24991: Extensions For CF7 <= 3.4.0 Authenticated (Contributor+) Insecure Direct Object Reference PoC, Patch Analysis & Rule
CVE-2026-24991 affects the Extensions For CF7 plugin for WordPress (up to version 3.4.0) with a medium severity (CVSS 4.3) IDOR vulnerability. Users should update to version 3.4.1 to mitigate unauthorized access risks.
March 18, 2026
CVE-2025-68848: amr cron manager <= 2.3 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-68848 affects the Amr Cron Manager plugin for WordPress (up to version 2.3) with a high severity CVSS score of 7.2. This stored XSS vulnerability allows unauthenticated attackers to inject scripts, necessitating immediate patching.
March 18, 2026
CVE-2025-12836: VK Google Job Posting Manager <= 1.2.23 Authenticated (Author+) Stored Cross-Site Scripting via Job Description Field PoC, Patch Analysis & Rule
CVE-2025-12836 affects the VK Google Job Posting Manager plugin (up to version 1.2.23) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should upgrade to version 1.2.24 to mitigate the risk of script injection.
March 18, 2026
CVE-2025-68999: Happy Addons for Elementor <= 3.20.4 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
CVE-2025-68999 affects the Happy Elementor Addons plugin (up to version 3.20.4) with a medium severity SQL injection vulnerability. Users should update to version 3.20.6 to mitigate risks of unauthorized database access.
March 18, 2026
CVE-2026-24548: Radio Player <= 2.0.91 Unauthenticated Server-Side Request Forgery PoC, Patch Analysis & Rule
CVE-2026-24548 affects the Radio Player plugin for WordPress (up to 2.0.91) with a CVSS score of 7.2. This high-severity Server-Side Request Forgery vulnerability allows unauthenticated attackers to make arbitrary web requests. Patching...
March 18, 2026
CVE-2026-1251: SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 Authenticated (Subscriber+) Insecure Direct Object Reference PoC, Patch Analysis & Rule
CVE-2026-1251 affects the SupportCandy plugin (up to v3.4.4) with a CVSS score of 5.4. Authenticated users can exploit this medium-severity vulnerability to access others' file attachments. Upgrade to v3.4.5 to mitigate risks.
March 18, 2026
CVE-2026-1720: WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation <= 1.4.24 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation PoC, Patch Analysis & Rule
CVE-2026-1720 affects the Optin plugin (v1.4.24) with a high severity CVSS score of 8.8. Authenticated attackers can exploit this to install arbitrary plugins. Update to v1.4.25 to mitigate this risk.
March 18, 2026
CVE-2026-24963: Booking for Appointments and Events Calendar – Amelia <= 1.2.38 Authenticated (Employee+) Privilege Escalation PoC, Patch Analysis & Rule
CVE-2026-24963 affects the AmeliaBooking plugin (up to v1.2.38) with a high severity CVSS score of 8.8. Authenticated users can escalate privileges to admin. Update to v2.0 to mitigate this vulnerability.
March 18, 2026
CVE-2026-3058: Seraphinite Accelerator <= 2.28.14 Authenticated (Subscriber+) Exposure of Sensitive Information to an Unauthorized Actor PoC, Patch Analysis & Rule
CVE-2026-3058 affects the Seraphinite Accelerator plugin (up to v2.28.14) with a CVSS score of 4.3. Authenticated users can access sensitive data. Update to v2.28.15 to mitigate this vulnerability.
March 18, 2026
CVE-2026-2355: My Calendar – Accessible Event Manager <= 3.7.3 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
CVE-2026-2355 affects the My Calendar plugin (up to version 3.7.3) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should update to the patched version to mitigate the risk of script injection.
March 18, 2026
CVE-2026-22479: Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress <= 2.2.0 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-22479 affects the Easy Post Submission plugin (up to v2.2.0) with a CVSS score of 5.3. It allows unauthorized access due to a missing capability check. Update to v2.3.0 to mitigate this risk.
March 18, 2026
CVE-2026-3056: Seraphinite Accelerator <= 2.28.14 Missing Authorization to Authenticated (Subscriber+) Log Clearing PoC, Patch Analysis & Rule
CVE-2026-3056 affects the Seraphinite Accelerator plugin (up to version 2.28.14) with a medium severity (CVSS 4.3) vulnerability. Update to version 2.28.15 to prevent unauthorized log modifications by authenticated users.
March 18, 2026
CVE-2026-1706: All-in-One Video Gallery <= 4.7.1 Reflected Cross-Site Scripting via 'vi' Parameter PoC, Patch Analysis & Rule
CVE-2026-1706 affects the All In One Video Gallery plugin for WordPress (up to version 4.7.1) with a medium severity score of 6.1. Users should update to version 4.7.5 to mitigate the reflected XSS vulnerability.
March 18, 2026
CVE-2023-7337: JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 Unauthenticated SQL Injection via ‘js-support-ticket-token-tkstatus’ Cookie PoC, Patch Analysis & Rule
CVE-2023-7337 affects the Js Support Ticket plugin (v2.8.2) with a high severity score of 7.5 due to SQL injection risks. Users should upgrade to version 2.8.3 to mitigate potential data exposure.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
