Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-2448: Page Builder by SiteOrigin <= 2.33.5 Authenticated (Contributor+) Local File Inclusion PoC, Patch Analysis & Rule

CVE-2026-2448 affects the SiteOrigin Panels plugin (up to v2.33.5) with a high severity (CVSS 8.8) local file inclusion vulnerability. Upgrade to v2.34.0 to mitigate risks of unauthorized file execution.
March 18, 2026

CVE-2026-28073: Wp EMember <= 10.2.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-28073 affects the Wp EMember plugin (up to version 10.2.2) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Ensure to update to the patched version to mitigate risks from potential attacks.
March 18, 2026

CVE-2026-2628: All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login <= 2.2.5 Authentication Bypass PoC, Patch Analysis & Rule

CVE-2026-2628 affects the Login With Azure plugin (up to version 2.2.5) with a critical CVSS score of 9.8. Unauthenticated attackers can bypass authentication, allowing unauthorized access. Update to the patched version immediately.
March 18, 2026

CVE-2026-1566: LatePoint <= 5.2.7 Authenticated (Agent+) Privilege Escalation PoC, Patch Analysis & Rule

CVE-2026-1566 affects the LatePoint plugin (up to 5.2.7) with a CVSS score of 8.8, allowing privilege escalation via password reset. Upgrade to version 5.2.8 to mitigate this high-severity vulnerability.
March 18, 2026

CVE-2026-3132: Master Addons for Elementor Premium <= 2.1.3 Authenticated (Subscriber+) Remote Code Execution via render_preview PoC, Patch Analysis & Rule

CVE-2026-3132 affects Master Addons Pro (up to v2.1.3) with a CVSS score of 8.8. This high-severity remote code execution vulnerability allows authenticated users to execute code on the server. Update to the patched version to mitigate...
March 18, 2026

CVE-2026-28038: Ultimate Addons for WPBakery Page Builder <= 3.21.1 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-28038 affects the Ultimate VC Addons plugin (up to version 3.21.1) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized actions by authenticated users. Ensure you update to the patched version to mitigate risks.
March 18, 2026

CVE-2026-28037: EventON <= 4.9.12 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-28037 affects the EventON plugin for WordPress (up to 4.9.12) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Ensure you update to the patched version to mitigate potential attacks.
March 18, 2026

CVE-2026-1542: Super Stage WP <= 1.0.1 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

CVE-2026-1542 affects the Super Stage WP plugin (up to v1.0.1) with a high severity (CVSS 8.1) file upload vulnerability. Update to v1.0.2 to mitigate risks of PHP Object Injection and potential unauthorized access.
March 18, 2026

CVE-2025-13673: Tutor LMS <= 3.9.6 Unauthenticated SQL Injection via coupon_code PoC, Patch Analysis & Rule

CVE-2025-13673 affects Tutor LMS versions up to 3.9.6, allowing unauthenticated SQL injection with a CVSS score of 7.5. Upgrade to 3.9.7 to mitigate risks of sensitive data exposure.
March 18, 2026

CVE-2026-2471: WP Mail Logging <= 1.15.0 Unauthenticated PHP Object Injection via Email Log Message Field PoC, Patch Analysis & Rule

CVE-2026-2471 affects WP Mail Logging plugin versions up to 1.15.0, with a CVSS score of 7.5. Unauthenticated attackers can exploit a file upload vulnerability. Update to version 1.16.0 to mitigate risks.
March 18, 2026

CVE-2026-28071: pixfort Core <= 3.2.22 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-28071 affects the Pixfort Core plugin (up to version 3.2.22) with a medium severity (CVSS 4.3) vulnerability. Authenticated users can exploit this to perform unauthorized actions; ensure you update to the patched version.
March 18, 2026

CVE-2026-27983: LMS Elementor Pro <= 1.0.4 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule

CVE-2026-27983 affects the LMS Elementor Pro plugin (up to version 1.0.4) with a critical CVSS score of 9.8, allowing unauthenticated privilege escalation. Users should update to the patched version to mitigate this risk.
March 18, 2026

CVE-2026-28072: pixfort Core <= 3.2.22 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-28072 affects the Pixfort Core plugin (up to v3.2.22) with a medium severity CVSS score of 6.1 due to reflected XSS. Users should update to the patched version to mitigate potential script injection attacks.
March 18, 2026

CVE-2026-28102: UberSlider Classic <= 2.5 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-28102 affects the UberSlider Classic plugin for WordPress (version 2.5 and earlier) with a medium severity (CVSS 6.1) XSS vulnerability. Users should update to the patched version to mitigate potential attacks.
March 18, 2026

CVE-2026-28100: UberSlider PerpetuumMobile <= 2.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-28100 affects the UberSlider PerpetuumMobile plugin (up to version 2.3) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Users should implement input sanitization and consider WAF coverage until a patch is released.
March 18, 2026

CVE-2026-2269: Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload PoC, Patch Analysis & Rule

CVE-2026-2269 affects the Uncanny Automator plugin (up to version 7.0.0.3) with a CVSS score of 7.2. Admins should upgrade to version 7.1.0 to mitigate a high-severity file upload vulnerability that could lead to remote code execution.
March 18, 2026

CVE-2026-28099: UberSlider Ultra <= 2.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-28099 affects the UberSlider Ultra plugin for WordPress (up to version 2.3) with a medium severity CVSS score of 6.1. Users should update to the patched version to mitigate reflected XSS risks.
March 18, 2026

CVE-2026-28101: UberSlider MouseInteraction <= 2.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-28101 affects the UberSlider MouseInteraction plugin (up to version 2.3) with a medium severity CVSS score of 6.1. Users should patch to mitigate the reflected XSS vulnerability.
March 18, 2026

CVE-2026-27984: Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets <= 4.1.3 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule

CVE-2026-27984 affects the Widget Options plugin (up to version 4.1.3) with a CVSS score of 8.8. It allows remote code execution by authenticated users. Upgrade to version 4.2.0 to mitigate this high-severity vulnerability.
March 18, 2026

CVE-2026-2831: MailArchiver <= 4.5.0 Authenticated (Admininistrator+) SQL Injection via 'logid' Parameter PoC, Patch Analysis & Rule

CVE-2026-2831 affects the Mailarchiver plugin (up to v4.5.0) with a medium severity score of 4.9. Admin-level users should update to v4.5.1 to mitigate SQL injection risks that could expose sensitive database information.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works