
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
June 28, 2026
CVE-2026-54808: WP Travel Gutenberg Blocks <= 3.9.4 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54808 affects WP Travel Blocks plugin versions up to 3.9.4 with a CVSS score of 7.5. Unauthenticated SQL Injection allows attackers to extract sensitive data. Upgrade to version 3.9.5 to mitigate this risk.
June 28, 2026
CVE-2026-54823: Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets <= 4.2.3 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule
CVE-2026-54823 affects the Widget Options plugin (up to v4.2.3) with a CVSS score of 8.8. It allows remote code execution for authenticated users. Update to v4.2.4 to mitigate this high-severity vulnerability.
June 27, 2026
CVE-2026-8095: Frontend File Manager Plugin <= 23.6 Authenticated (Subscriber+) Arbitrary File Deletion PoC, Patch Analysis & Rule
CVE-2026-8095 affects the Nmedia User File Uploader plugin (up to version 23.6) with a CVSS score of 8.1. Authenticated attackers can delete arbitrary files, risking sensitive data exposure. Ensure timely patching to mitigate this risk.
June 27, 2026
CVE-2026-56012: Media Library Assistant <= 3.35 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-56012 affects the Media Library Assistant plugin for WordPress (up to version 3.35) with a medium severity (CVSS 6.5) SQL injection vulnerability. Update to version 3.36 to mitigate risks from authenticated attackers.
June 27, 2026
CVE-2026-56008: Avada (Fusion) Builder <= 3.15.4 Authenticated (Contributor+) Privilege Escalation PoC, Patch Analysis & Rule
CVE-2026-56008 affects the Fusion Builder plugin for WordPress (up to v3.15.4) with a high severity CVSS score of 8.8. Authenticated users can escalate privileges, highlighting the need for immediate patching.
June 27, 2026
CVE-2026-56024: WP Easy Pay – Payment and Donation form Builder for Square <= 4.5.0 Cross-Site Request Forgery PoC, Patch Analysis & Rule
CVE-2026-56024 affects WP Easy Pay plugin versions up to 4.5.0, with a CVSS score of 4.3. This medium-severity CSRF vulnerability allows unauthorized actions. Update to the patched version to mitigate risks.
June 27, 2026
CVE-2026-54833: Enable CORS <= 2.0.3 Backdoor PoC, Patch Analysis & Rule
CVE-2026-54833 affects the Enable CORS plugin (up to version 2.0.3) with a critical CVSS score of 9.8. Unauthenticated attackers can exploit a backdoor for privileged access. Update to version 2.0.4 to mitigate this risk.
June 27, 2026
CVE-2026-54843: MDTF – Meta Data and Taxonomies Filter <= 1.3.7 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54843 affects the Wp Meta Data Filter And Taxonomy Filter plugin (v1.3.7 and earlier) with a high severity CVSS score of 7.5. Unauthenticated SQL injection can expose sensitive data; patching is essential.
June 27, 2026
CVE-2026-54848: WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce <= 4.7.3 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
CVE-2026-54848 affects the Woosquare plugin (up to v4.7.3) with a CVSS score of 5.3, allowing unauthenticated access to sensitive data. Update to v4.7.4 to mitigate this remote code execution vulnerability.
June 27, 2026
CVE-2026-54846: Syncee Premium Dropshipping & Wholesale <= 1.0.27 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-54846 affects the Syncee Global Dropshipping plugin (up to v1.0.27) with a CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability, making it crucial to update to v1.0.28 for protection.
June 27, 2026
CVE-2026-56006: Interactive Content – H5P <= 1.17.6 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-56006 affects the H5P plugin for WordPress (up to version 1.17.6) with a medium severity (CVSS 6.1) XSS vulnerability. Upgrade to version 1.17.7 to mitigate potential attacks.
June 27, 2026
CVE-2026-54841: Vitepos – Point of Sale (POS) for WooCommerce <= 3.4.2 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
CVE-2026-54841 affects the Vitepos Lite plugin for WordPress (up to version 3.4.2) with a CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability to access sensitive data. Update to version 3.4.3 to mitigate risks.
June 27, 2026
CVE-2026-54845: MDTF – Meta Data and Taxonomies Filter <= 1.3.8 Unauthenticated Local File Inclusion PoC, Patch Analysis & Rule
CVE-2026-54845 affects the Wp Meta Data Filter And Taxonomy Filter plugin (up to 1.3.8) with a CVSS of 8.1. This high-severity vulnerability allows unauthenticated local file inclusion, risking server compromise. Patching is essential.
June 27, 2026
CVE-2026-54847: Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator <= 8.3.9 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-54847 affects the Stylish Cost Calculator plugin for WordPress (up to v8.3.9) due to a missing capability check, allowing unauthorized access. Upgrade to v8.3.10 to mitigate this medium severity vulnerability.
June 27, 2026
CVE-2026-54842: Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini <= 1.4.25 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-54842 affects the Royal MCP plugin for WordPress (up to version 1.4.25) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized access. Update to version 1.4.26 to mitigate risks.
June 27, 2026
CVE-2026-54838: WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.8 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54838 affects the WC Vendors plugin (up to version 2.6.8) with a medium severity SQL injection vulnerability (CVSS 6.5). Update to version 2.6.9 to mitigate the risk of data extraction by authenticated attackers.
June 27, 2026
CVE-2026-56007: Ocean Product Sharing <= 2.2.2 Authenticated (Shop manager+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-56007 affects the Ocean Product Sharing plugin (up to 2.2.2) with a medium severity (CVSS 4.4) Stored XSS vulnerability. Patch to version 2.2.3 to mitigate risks from authenticated attackers injecting scripts.
June 27, 2026
CVE-2026-54839: Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
CVE-2026-54839 affects the Trinity Backup plugin (up to v2.0.9) with a CVSS score of 5.3, exposing sensitive data to unauthenticated attackers. Update to v2.0.10 to mitigate this vulnerability.
June 27, 2026
CVE-2026-54849: Premmerce Wishlist for WooCommerce <= 1.1.11 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54849 affects the Premmerce WooCommerce Wishlist plugin (up to 1.1.11) with a high severity SQL injection vulnerability (CVSS 7.5). Users should upgrade to version 1.1.12 to mitigate potential data exposure.
June 27, 2026
CVE-2026-54837: Intranet & Private Site – All-In-One Intranet <= 1.8.1 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-54837 affects the All In One Intranet plugin for WordPress (up to version 1.8.1) with a medium severity (CVSS 5.3). Update to version 1.9.0 to mitigate unauthorized access risks.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
