Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-1674: Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema() PoC, Patch Analysis & Rule

CVE-2026-1674 affects the Gutena Forms plugin (up to v1.6.0) with a medium severity (CVSS 6.5). Authenticated users can modify site options, potentially disrupting service. Upgrade to v1.6.1 to mitigate this risk.
March 18, 2026

CVE-2026-2732: Enable Media Replace <= 4.1.7 Improper Authorization to Authenticated (Author+) Arbitrary Attachment Change via Background Replace PoC, Patch Analysis & Rule

CVE-2026-2732 affects the Enable Media Replace plugin (up to v4.1.7) with a medium severity (CVSS 5.4) vulnerability allowing unauthorized data modification. Users should update to v4.1.8 to mitigate this risk.
March 18, 2026

CVE-2026-1236: Envira Gallery for WordPress <= 1.12.3 Authenticated (Author+) Stored Cross-Site Scripting via 'justified_gallery_theme' Parameter via REST API PoC, Patch Analysis & Rule

CVE-2026-1236 affects Envira Gallery Lite (up to v1.12.3) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should update to v1.12.4 to mitigate risks from potential script injections.
March 18, 2026

CVE-2026-2363: WP-Members Membership Plugin <= 3.5.5.1 Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-2363 affects the WP-Members Membership Plugin (up to 3.5.5.1) with a medium severity SQL injection (CVSS 6.5). Update to version 3.5.6 to mitigate risks of data exposure from authenticated attacks.
March 18, 2026

CVE-2026-1980: WPBookit <= 1.0.8 Missing Authorization to Unauthenticated Sensitive Customer Data Exposure PoC, Patch Analysis & Rule

CVE-2026-1980 affects the WPBookit plugin (up to v1.0.8) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access to sensitive customer data. Upgrade to v1.0.9 to mitigate this risk.
March 18, 2026

CVE-2026-1945: WPBookit <= 1.0.8 Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and 'wpb_user_email' Parameters PoC, Patch Analysis & Rule

CVE-2026-1945 affects WPBookit plugin version 1.0.8 with a high severity CVSS score of 7.2. Unauthenticated attackers can exploit a stored XSS vulnerability. Upgrade to version 1.0.9 to mitigate this risk.
March 18, 2026

CVE-2026-3523: Apocalypse Meow <= 22.1.0 Authenticated (Administrator+) SQL Injection via 'type' Parameter PoC, Patch Analysis & Rule

CVE-2026-3523 affects the Apocalypse Meow plugin for WordPress (up to v22.1.0) with a medium severity (CVSS 4.9) SQL injection vulnerability. Upgrade to v23.0.0 to mitigate risks of unauthorized database access.
March 18, 2026

CVE-2026-2289: Taskbuilder – Project Management & Task Management Tool With Kanban Board <= 5.0.3 Authenticated (Administrator+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-2289 affects the Taskbuilder plugin for WordPress (up to version 5.0.3) with a medium severity (CVSS 4.4) stored XSS vulnerability. Update to version 5.0.4 to mitigate risks associated with this flaw.
March 18, 2026

CVE-2026-2292: Morkva UA Shipping <= 1.7.9 Authenticated (Administrator+) Stored Cross-Site Scripting via 'Weight, kg' Field PoC, Patch Analysis & Rule

CVE-2026-2292 affects the Morkva UA Shipping plugin (up to v1.7.9) with a medium severity (CVSS 4.4) stored XSS vulnerability. Update to v1.7.10 to mitigate risks associated with insufficient input sanitization.
March 18, 2026

CVE-2026-22460: FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.4.2 Unauthenticated Arbitrary File Deletion PoC, Patch Analysis & Rule

CVE-2026-22460 affects the Formgent plugin (v1.4.2 and below) with a critical CVSS score of 9.1. Unauthenticated attackers can delete arbitrary files, risking remote code execution. Update to version 1.5.0 to mitigate this vulnerability.
March 18, 2026

CVE-2026-28039: wpDataTables (Premium) <= 6.5.0.1 Unauthenticated Local File Inclusion PoC, Patch Analysis & Rule

CVE-2026-28039 affects wpDataTables plugin version 6.5.0.1, allowing unauthenticated Local File Inclusion with a CVSS score of 8.1. Upgrade to version 6.5.0.2 to mitigate this high-severity vulnerability.
March 18, 2026

CVE-2026-1273: PostX <= 5.0.8 Authenticated (Administrator+) Server-Side Request Forgery via REST API Endpoints PoC, Patch Analysis & Rule

CVE-2026-1273 affects the Ultimate Post plugin (v5.0.8) with a high severity score of 7.2. Authenticated attackers can exploit SSRF vulnerabilities. Upgrade to v5.0.9 to mitigate risks.
March 18, 2026

CVE-2026-1651: Email Subscribers & Newsletters <= 5.9.16 Authenticated (Administrator+) SQL Injection via 'workflow_ids' Parameter PoC, Patch Analysis & Rule

CVE-2026-1651 affects the Email Subscribers plugin (up to v5.9.16) with a medium severity (CVSS 6.5) SQL injection vulnerability. Upgrade to v5.9.17 to mitigate risks of data exposure for admin users.
March 18, 2026

CVE-2026-2568: WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-2568 affects the Cf7 Zendesk plugin for WordPress (up to version 1.1.5) with a high severity CVSS of 7.2. Update to version 1.1.6 to mitigate stored XSS risks from form submissions.
March 18, 2026

CVE-2026-24385: Podlove Web Player <= 5.9.1 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule

CVE-2026-24385 affects the Podlove Web Player plugin (up to version 5.9.1) with a high severity CVSS score of 7.5. Users should upgrade to version 5.9.2 to mitigate the risk of PHP Object Injection vulnerabilities.
March 18, 2026

CVE-2026-22459: WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales <= 1.7.4 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-22459 affects the Easy Sticky Sidebar plugin (up to v1.7.4) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Upgrade to v2.0.0 to mitigate risks.
March 18, 2026

CVE-2026-1492: User Registration & Membership <= 5.1.2 Unauthenticated Privilege Escalation via Membership Registration PoC, Patch Analysis & Rule

CVE-2026-1492 affects the User Registration plugin for WordPress (up to version 5.1.2) with a critical CVSS score of 9.8. Update to version 5.1.3 to mitigate unauthenticated privilege escalation risks.
March 18, 2026

CVE-2026-1487: LatePoint <= 5.2.7 Authenticated (Administrator+) SQL Injection via JSON Import PoC, Patch Analysis & Rule

CVE-2026-1487 affects the LatePoint plugin (up to v5.2.7) with a medium severity (CVSS 6.5) SQL injection vulnerability. Update to v5.2.8 to mitigate risks from authenticated attackers exploiting JSON import.
March 18, 2026

CVE-2026-1336: AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.5 Missing Authorization to Unauthenticated API Key Modification PoC, Patch Analysis & Rule

CVE-2026-1336 affects Ays Chatgpt Assistant plugin versions up to 2.7.5, allowing unauthorized access to sensitive data. Upgrade to version 2.7.6 to mitigate this medium severity vulnerability.
March 18, 2026

CVE-2026-3180: Contest Gallery <= 28.1.4 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2026-3180 affects the Contest Gallery plugin (up to version 28.1.4) with a high severity CVSS score of 7.5 due to SQL injection vulnerabilities. Update to version 28.1.5 to mitigate risks from unauthenticated attacks.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works