Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-28104: Site Suggest <= 1.3.9 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-28104 affects the Site Suggest plugin for WordPress (up to version 1.3.9) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability, so ensure you update to the patched version.
March 18, 2026

CVE-2026-28103: Responsive Zoom In/Out Slider WordPress Plugin <= 5.4.5 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-28103 affects the Lbg_zoominoutslider plugin (up to version 5.4.5) with a medium severity CVSS score of 6.1. Ensure proper input sanitization to mitigate reflected XSS risks.
March 18, 2026

CVE-2026-23799: Tutor LMS – eLearning and online course solution <= 3.9.5 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-23799 affects Tutor LMS plugin versions up to 3.9.5, allowing authenticated users to perform unauthorized actions. Update to version 3.9.6 to mitigate this medium severity vulnerability.
March 18, 2026

CVE-2026-22390: Builderall for WordPress <= 3.0.1 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule

CVE-2026-22390 affects the Builderall Cheetah For WP plugin (up to version 3.0.1) with a high severity score of 8.8. Authenticated attackers can execute remote code, making immediate patching essential.
March 18, 2026

CVE-2026-2506: EM Cost Calculator <= 2.3.1 Unauthenticated Stored Cross-Site Scripting via 'customer_name' PoC, Patch Analysis & Rule

CVE-2026-2506 affects the Cost Calculator plugin for WordPress (up to v2.3.1) with a medium severity (CVSS 6.1) stored XSS vulnerability. Unauthenticated attackers can inject scripts, impacting admin security. Patching is essential.
March 18, 2026

CVE-2026-27354: WooCommerce Coming Soon Product with Countdown <= 5.0 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-27354 affects the Woo Coming Soon Product plugin for WordPress (up to v5.0) with a CVSS score of 6.4. Authenticated users can exploit this medium-severity XSS vulnerability, so ensure you update to the patched version.
March 18, 2026

CVE-2026-23802: AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.3.2 Authenticated (Editor+) Arbitrary File Upload PoC, Patch Analysis & Rule

CVE-2026-23802 reveals a high-severity file upload vulnerability in the Ai Engine plugin (versions up to 3.3.2). Update to 3.3.3 to mitigate risks of arbitrary file uploads and potential remote code execution.
March 18, 2026

CVE-2025-69343: Theater for WordPress <= 0.19 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-69343 affects the Theatre plugin for WordPress (up to v0.19) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit stored XSS, making timely patching essential to mitigate risks.
March 18, 2026

CVE-2025-69338: Riode Core <= 1.6.26 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2025-69338 affects the Riode Core plugin for WordPress, with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated attackers to extract sensitive data. Update to the patched version to mitigate...
March 18, 2026

CVE-2026-2499: Custom Logo <= 2.2 Authenticated (Administrator+) Stored Cross-Site Scripting via Logo Path Setting PoC, Patch Analysis & Rule

CVE-2026-2499 affects the Custom Logo plugin for WordPress (up to v2.2) with a medium severity (CVSS 4.4) XSS vulnerability. Admins should patch to prevent script injection risks on multisite installations.
March 18, 2026

CVE-2026-23798: PowerPress Podcasting plugin by Blubrry <= 11.15.10 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule

CVE-2026-23798 affects the PowerPress plugin for WordPress (up to 11.15.10) with a high severity CVSS of 7.5. Authenticated attackers can exploit a PHP object injection vulnerability. Update to version 11.15.11 to mitigate risks.
March 18, 2026

CVE-2026-2694: The Events Calendar <= 6.15.16 Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API PoC, Patch Analysis & Rule

CVE-2026-2694 affects The Events Calendar plugin (up to 6.15.16) with a medium severity (CVSS 5.4) vulnerability. Authenticated users can modify or delete events via the REST API. Update to version 6.15.16.1 to mitigate risks.
March 18, 2026

CVE-2026-27359: Awa Plugins <= 1.4.4 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-27359 affects Awa Plugins for WordPress (up to version 1.4.4) with a medium severity CVSS score of 6.1. Patching is essential to mitigate reflected XSS risks from unauthenticated attackers.
March 18, 2026

CVE-2025-69340: WeDesignTech Ultimate Booking Addon <= 1.0.3 Missing Authorization PoC, Patch Analysis & Rule

CVE-2025-69340 affects the WeDesignTech Ultimate Booking Addon plugin (up to v1.0.3) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Users should update to the patched version to mitigate risks.
March 18, 2026

CVE-2026-27361: Responsive Posts Carousel WordPress Plugin <= 15.1 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-27361 affects the Responsive Posts Carousel Pro plugin (up to v15.1) with a CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability, so ensure you update to the patched version to mitigate risks.
March 18, 2026

CVE-2026-2410: Disable Admin Notices – Hide Dashboard Notifications <= 1.4.2 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule

CVE-2026-2410 affects the Disable Admin Notices plugin (up to v1.4.2) with a medium severity CVSS score of 4.3. Update to v1.4.3 to mitigate the CSRF vulnerability that allows unauthorized URL modifications.
March 18, 2026

CVE-2026-27363: Bakery Autoresponder Addon <= 1.0.6 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-27363 affects the Vc Autoresponder Addon plugin for WordPress (up to version 1.0.6) with a CVSS score of 7.2. This high-severity XSS vulnerability allows unauthenticated attackers to inject scripts. Patching is essential.
March 18, 2026

CVE-2026-27344: Scientific and Interactive Blocks – inseri core <= 1.0.5 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-27344 affects the Inseri Core plugin for WordPress (up to version 1.0.5) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability, so patching is essential.
March 18, 2026

CVE-2026-27362: Bakery Autoresponder Addon <= 1.0.6 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-27362 affects the Vc Autoresponder Addon plugin for WordPress (up to version 1.0.6) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability, so patching is essential.
March 18, 2026

CVE-2026-2301: Post Duplicator <= 3.0.8 Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter PoC, Patch Analysis & Rule

CVE-2026-2301 affects the Post Duplicator plugin (up to version 3.0.8) with a medium severity (CVSS 4.3) vulnerability. Patch to version 3.0.9 to prevent unauthorized meta key insertion by authenticated users.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works