Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

June 28, 2026

CVE-2026-54808: WP Travel Gutenberg Blocks <= 3.9.4 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2026-54808 affects WP Travel Blocks plugin versions up to 3.9.4 with a CVSS score of 7.5. Unauthenticated SQL Injection allows attackers to extract sensitive data. Upgrade to version 3.9.5 to mitigate this risk.
June 28, 2026

CVE-2026-54823: Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets <= 4.2.3 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule

CVE-2026-54823 affects the Widget Options plugin (up to v4.2.3) with a CVSS score of 8.8. It allows remote code execution for authenticated users. Update to v4.2.4 to mitigate this high-severity vulnerability.
June 27, 2026

CVE-2026-8095: Frontend File Manager Plugin <= 23.6 Authenticated (Subscriber+) Arbitrary File Deletion PoC, Patch Analysis & Rule

CVE-2026-8095 affects the Nmedia User File Uploader plugin (up to version 23.6) with a CVSS score of 8.1. Authenticated attackers can delete arbitrary files, risking sensitive data exposure. Ensure timely patching to mitigate this risk.
June 27, 2026

CVE-2026-56012: Media Library Assistant <= 3.35 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule

CVE-2026-56012 affects the Media Library Assistant plugin for WordPress (up to version 3.35) with a medium severity (CVSS 6.5) SQL injection vulnerability. Update to version 3.36 to mitigate risks from authenticated attackers.
June 27, 2026

CVE-2026-56008: Avada (Fusion) Builder <= 3.15.4 Authenticated (Contributor+) Privilege Escalation PoC, Patch Analysis & Rule

CVE-2026-56008 affects the Fusion Builder plugin for WordPress (up to v3.15.4) with a high severity CVSS score of 8.8. Authenticated users can escalate privileges, highlighting the need for immediate patching.
June 27, 2026

CVE-2026-56024: WP Easy Pay – Payment and Donation form Builder for Square <= 4.5.0 Cross-Site Request Forgery PoC, Patch Analysis & Rule

CVE-2026-56024 affects WP Easy Pay plugin versions up to 4.5.0, with a CVSS score of 4.3. This medium-severity CSRF vulnerability allows unauthorized actions. Update to the patched version to mitigate risks.
June 27, 2026

CVE-2026-54833: Enable CORS <= 2.0.3 Backdoor PoC, Patch Analysis & Rule

CVE-2026-54833 affects the Enable CORS plugin (up to version 2.0.3) with a critical CVSS score of 9.8. Unauthenticated attackers can exploit a backdoor for privileged access. Update to version 2.0.4 to mitigate this risk.
June 27, 2026

CVE-2026-54843: MDTF – Meta Data and Taxonomies Filter <= 1.3.7 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2026-54843 affects the Wp Meta Data Filter And Taxonomy Filter plugin (v1.3.7 and earlier) with a high severity CVSS score of 7.5. Unauthenticated SQL injection can expose sensitive data; patching is essential.
June 27, 2026

CVE-2026-54848: WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce <= 4.7.3 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

CVE-2026-54848 affects the Woosquare plugin (up to v4.7.3) with a CVSS score of 5.3, allowing unauthenticated access to sensitive data. Update to v4.7.4 to mitigate this remote code execution vulnerability.
June 27, 2026

CVE-2026-54846: Syncee Premium Dropshipping & Wholesale <= 1.0.27 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-54846 affects the Syncee Global Dropshipping plugin (up to v1.0.27) with a CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability, making it crucial to update to v1.0.28 for protection.
June 27, 2026

CVE-2026-56006: Interactive Content – H5P <= 1.17.6 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-56006 affects the H5P plugin for WordPress (up to version 1.17.6) with a medium severity (CVSS 6.1) XSS vulnerability. Upgrade to version 1.17.7 to mitigate potential attacks.
June 27, 2026

CVE-2026-54841: Vitepos – Point of Sale (POS) for WooCommerce <= 3.4.2 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

CVE-2026-54841 affects the Vitepos Lite plugin for WordPress (up to version 3.4.2) with a CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability to access sensitive data. Update to version 3.4.3 to mitigate risks.
June 27, 2026

CVE-2026-54845: MDTF – Meta Data and Taxonomies Filter <= 1.3.8 Unauthenticated Local File Inclusion PoC, Patch Analysis & Rule

CVE-2026-54845 affects the Wp Meta Data Filter And Taxonomy Filter plugin (up to 1.3.8) with a CVSS of 8.1. This high-severity vulnerability allows unauthenticated local file inclusion, risking server compromise. Patching is essential.
June 27, 2026

CVE-2026-54847: Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator <= 8.3.9 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-54847 affects the Stylish Cost Calculator plugin for WordPress (up to v8.3.9) due to a missing capability check, allowing unauthorized access. Upgrade to v8.3.10 to mitigate this medium severity vulnerability.
June 27, 2026

CVE-2026-54842: Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini <= 1.4.25 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-54842 affects the Royal MCP plugin for WordPress (up to version 1.4.25) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized access. Update to version 1.4.26 to mitigate risks.
June 27, 2026

CVE-2026-54838: WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.8 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule

CVE-2026-54838 affects the WC Vendors plugin (up to version 2.6.8) with a medium severity SQL injection vulnerability (CVSS 6.5). Update to version 2.6.9 to mitigate the risk of data extraction by authenticated attackers.
June 27, 2026

CVE-2026-56007: Ocean Product Sharing <= 2.2.2 Authenticated (Shop manager+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-56007 affects the Ocean Product Sharing plugin (up to 2.2.2) with a medium severity (CVSS 4.4) Stored XSS vulnerability. Patch to version 2.2.3 to mitigate risks from authenticated attackers injecting scripts.
June 27, 2026

CVE-2026-54839: Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

CVE-2026-54839 affects the Trinity Backup plugin (up to v2.0.9) with a CVSS score of 5.3, exposing sensitive data to unauthenticated attackers. Update to v2.0.10 to mitigate this vulnerability.
June 27, 2026

CVE-2026-54849: Premmerce Wishlist for WooCommerce <= 1.1.11 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2026-54849 affects the Premmerce WooCommerce Wishlist plugin (up to 1.1.11) with a high severity SQL injection vulnerability (CVSS 7.5). Users should upgrade to version 1.1.12 to mitigate potential data exposure.
June 27, 2026

CVE-2026-54837: Intranet & Private Site – All-In-One Intranet <= 1.8.1 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-54837 affects the All In One Intranet plugin for WordPress (up to version 1.8.1) with a medium severity (CVSS 5.3). Update to version 1.9.0 to mitigate unauthorized access risks.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works