
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1305: Japanized for WooCommerce <= 2.8.4 Missing Authorization to Unauthenticated Paidy Order Manipulation PoC, Patch Analysis & Rule
CVE-2026-1305 affects the Woocommerce For Japan plugin (up to 2.8.4) with a medium severity (CVSS 5.3) remote code execution vulnerability. Update to version 2.8.5 to mitigate unauthorized payment processing risks.
March 18, 2026
CVE-2026-2362: WP Accessibility <= 2.3.1 Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via 'alt' Attribute PoC, Patch Analysis & Rule
CVE-2026-2362 affects the WP Accessibility plugin (up to version 2.3.1) with a medium severity (CVSS 6.4) XSS vulnerability. Patch to version 2.3.2 to mitigate risks from authenticated attackers exploiting the 'Long Description UI' feature.
March 18, 2026
CVE-2026-1558: WP Recipe Maker <= 10.3.2 Insecure Direct Object Reference to Unauthenticated Arbitrary Post Metadata Modification via 'recipeId' Parameter PoC, Patch Analysis & Rule
CVE-2026-1558 affects the WP Recipe Maker plugin (up to version 10.3.2) with a medium severity (CVSS 5.3) vulnerability. Users should upgrade to version 10.3.3 to prevent unauthorized access to post metadata.
March 18, 2026
CVE-2025-14142: Electric Enquiries <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'button' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2025-14142 affects the Electric Enquiries plugin (up to v1.1) with a medium severity (CVSS 6.4) stored XSS vulnerability. Ensure to update to the patched version to mitigate risks from authenticated attackers.
March 18, 2026
CVE-2026-2383: Simple Download Monitor <= 4.0.5 Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field PoC, Patch Analysis & Rule
CVE-2026-2383 affects the Simple Download Monitor plugin (up to v4.0.5) with a medium severity (CVSS 6.4) cross-site scripting vulnerability. Users should update to v4.0.6 to mitigate risks from authenticated attackers.
March 18, 2026
CVE-2026-2428: Fluent Forms Pro Add On Pack <= 6.1.17 Missing Authorization to Unauthenticated Payment Status modification PoC, Patch Analysis & Rule
CVE-2026-2428 affects the Fluent Forms Pro plugin (up to v6.1.17) with a CVSS score of 7.5. It allows unauthenticated attackers to manipulate payment notifications. Ensure you update to the patched version to mitigate this risk.
March 18, 2026
CVE-2026-28122: ListingPro Plugin <= 2.9.8 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-28122 affects the ListingPro Plugin for WordPress (up to version 2.9.8) with a medium severity CVSS score of 6.1. Users should update to the patched version to mitigate the reflected XSS risk.
March 18, 2026
CVE-2025-14149: Xpro Addons — 140+ Widgets for Elementor <= 1.4.24 Authenticated (Contributor+) Stored Cross-Site Scripting via Image Scroller Widget box link PoC, Patch Analysis & Rule
CVE-2025-14149 affects the Xpro Elementor Addons plugin (up to v1.4.24) with a medium severity (CVSS 6.4) stored XSS vulnerability. Authenticated attackers can exploit this flaw, so patching is essential for security.
March 18, 2026
CVE-2024-10938: OVRI Payment 1.7.0 Malicious .htaccess directive PoC, Patch Analysis & Rule
CVE-2024-10938 affects the Moneytigo plugin (v1.7.0) with a medium severity (CVSS 6.5). Malicious .htaccess files can block legitimate scripts. Update to the patched version to mitigate risks.
March 18, 2026
CVE-2026-28134: JetEngine <= 3.7.2 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule
CVE-2026-28134 affects Jet Engine plugin versions up to 3.7.2, allowing remote code execution for authenticated users. With a CVSS score of 8.8, it's crucial to update to the patched version to mitigate risks.
March 18, 2026
CVE-2026-28133: Filr – Secure document library <= 1.2.13 Authenticated (Contributor+) Arbitrary File Uploads PoC, Patch Analysis & Rule
CVE-2026-28133 affects the Filr Protection plugin (v1.2.13 and below) with a CVSS score of 8.8. It allows authenticated users to upload arbitrary files, risking remote code execution. Update to v1.2.14 to mitigate this vulnerability.
March 18, 2026
CVE-2026-28135: Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-28135 affects the Royal Elementor Addons plugin (up to v1.7.1049) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Update to v1.7.1050 to mitigate this issue.
March 18, 2026
CVE-2026-28078: Directory Listings WordPress plugin – uListing <= 2.2.0 Authenticated (Editor+) Arbitrary File Download PoC, Patch Analysis & Rule
CVE-2026-28078 affects the uListing WordPress plugin (up to version 2.2.0) with a medium severity CVSS of 4.9. Authenticated attackers can exploit this file upload vulnerability to access sensitive server files. Patching is recommended.
March 18, 2026
CVE-2026-28112: AllInOne Banner Rotator <= 3.8 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-28112 affects the All In One BannerRotator plugin (up to version 3.8) with a medium severity CVSS score of 6.1 due to reflected XSS. Users should update to the patched version to mitigate potential attacks.
March 18, 2026
CVE-2026-28115: WP Attractive Donations System Easy Stripe & Paypal donations <= 1.25 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-28115 affects the WP Attractive Donations System plugin (up to v1.25) with a high severity (CVSS 7.5) SQL injection vulnerability. Unauthenticated attackers can exploit this flaw to access sensitive database information...
March 18, 2026
CVE-2026-28108: LambertGroup AllInOne Banner with Thumbnails <= 3.8 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-28108 affects the All In One ThumbnailsBanner plugin for WordPress, with a medium severity CVSS score of 6.1. Users should update from version 3.8 to mitigate the reflected XSS risk from insufficient input sanitization.
March 18, 2026
CVE-2026-28113: Ultimate Learning Pro <= 3.9.1 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-28113 affects the Indeed Learning Pro plugin (v3.9.1) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Ensure to update to the patched version to mitigate potential attacks.
March 18, 2026
CVE-2026-28127: Lawyer Directory <= 1.3.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-28127 affects the Lawyer Directory plugin for WordPress (up to v1.3.2) with a high severity CVSS score of 7.2 due to stored XSS. Users should update to the patched version to mitigate potential attacks.
March 18, 2026
CVE-2026-28109: LambertGroup AllInOne Content Slider <= 3.8 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-28109 affects the All In One ContentSlider plugin for WordPress (up to version 3.8) with a medium severity (CVSS 6.1) XSS vulnerability. Users should update to the patched version to mitigate risks from potential script injections.
March 18, 2026
CVE-2026-28110: LambertGroup AllInOne Banner with Playlist <= 3.8 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-28110 affects the All In One BannerWithPlaylist plugin for WordPress, with a CVSS score of 6.1. Users should update from version 3.8 to mitigate reflected XSS risks from insufficient input sanitization.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
