
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-28104: Site Suggest <= 1.3.9 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-28104 affects the Site Suggest plugin for WordPress (up to version 1.3.9) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability, so ensure you update to the patched version.
March 18, 2026
CVE-2026-28103: Responsive Zoom In/Out Slider WordPress Plugin <= 5.4.5 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-28103 affects the Lbg_zoominoutslider plugin (up to version 5.4.5) with a medium severity CVSS score of 6.1. Ensure proper input sanitization to mitigate reflected XSS risks.
March 18, 2026
CVE-2026-23799: Tutor LMS – eLearning and online course solution <= 3.9.5 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-23799 affects Tutor LMS plugin versions up to 3.9.5, allowing authenticated users to perform unauthorized actions. Update to version 3.9.6 to mitigate this medium severity vulnerability.
March 18, 2026
CVE-2026-22390: Builderall for WordPress <= 3.0.1 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule
CVE-2026-22390 affects the Builderall Cheetah For WP plugin (up to version 3.0.1) with a high severity score of 8.8. Authenticated attackers can execute remote code, making immediate patching essential.
March 18, 2026
CVE-2026-2506: EM Cost Calculator <= 2.3.1 Unauthenticated Stored Cross-Site Scripting via 'customer_name' PoC, Patch Analysis & Rule
CVE-2026-2506 affects the Cost Calculator plugin for WordPress (up to v2.3.1) with a medium severity (CVSS 6.1) stored XSS vulnerability. Unauthenticated attackers can inject scripts, impacting admin security. Patching is essential.
March 18, 2026
CVE-2026-27354: WooCommerce Coming Soon Product with Countdown <= 5.0 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-27354 affects the Woo Coming Soon Product plugin for WordPress (up to v5.0) with a CVSS score of 6.4. Authenticated users can exploit this medium-severity XSS vulnerability, so ensure you update to the patched version.
March 18, 2026
CVE-2026-23802: AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.3.2 Authenticated (Editor+) Arbitrary File Upload PoC, Patch Analysis & Rule
CVE-2026-23802 reveals a high-severity file upload vulnerability in the Ai Engine plugin (versions up to 3.3.2). Update to 3.3.3 to mitigate risks of arbitrary file uploads and potential remote code execution.
March 18, 2026
CVE-2025-69343: Theater for WordPress <= 0.19 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-69343 affects the Theatre plugin for WordPress (up to v0.19) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit stored XSS, making timely patching essential to mitigate risks.
March 18, 2026
CVE-2025-69338: Riode Core <= 1.6.26 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2025-69338 affects the Riode Core plugin for WordPress, with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated attackers to extract sensitive data. Update to the patched version to mitigate...
March 18, 2026
CVE-2026-2499: Custom Logo <= 2.2 Authenticated (Administrator+) Stored Cross-Site Scripting via Logo Path Setting PoC, Patch Analysis & Rule
CVE-2026-2499 affects the Custom Logo plugin for WordPress (up to v2.2) with a medium severity (CVSS 4.4) XSS vulnerability. Admins should patch to prevent script injection risks on multisite installations.
March 18, 2026
CVE-2026-23798: PowerPress Podcasting plugin by Blubrry <= 11.15.10 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
CVE-2026-23798 affects the PowerPress plugin for WordPress (up to 11.15.10) with a high severity CVSS of 7.5. Authenticated attackers can exploit a PHP object injection vulnerability. Update to version 11.15.11 to mitigate risks.
March 18, 2026
CVE-2026-2694: The Events Calendar <= 6.15.16 Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API PoC, Patch Analysis & Rule
CVE-2026-2694 affects The Events Calendar plugin (up to 6.15.16) with a medium severity (CVSS 5.4) vulnerability. Authenticated users can modify or delete events via the REST API. Update to version 6.15.16.1 to mitigate risks.
March 18, 2026
CVE-2026-27359: Awa Plugins <= 1.4.4 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-27359 affects Awa Plugins for WordPress (up to version 1.4.4) with a medium severity CVSS score of 6.1. Patching is essential to mitigate reflected XSS risks from unauthenticated attackers.
March 18, 2026
CVE-2025-69340: WeDesignTech Ultimate Booking Addon <= 1.0.3 Missing Authorization PoC, Patch Analysis & Rule
CVE-2025-69340 affects the WeDesignTech Ultimate Booking Addon plugin (up to v1.0.3) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Users should update to the patched version to mitigate risks.
March 18, 2026
CVE-2026-27361: Responsive Posts Carousel WordPress Plugin <= 15.1 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-27361 affects the Responsive Posts Carousel Pro plugin (up to v15.1) with a CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability, so ensure you update to the patched version to mitigate risks.
March 18, 2026
CVE-2026-2410: Disable Admin Notices – Hide Dashboard Notifications <= 1.4.2 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule
CVE-2026-2410 affects the Disable Admin Notices plugin (up to v1.4.2) with a medium severity CVSS score of 4.3. Update to v1.4.3 to mitigate the CSRF vulnerability that allows unauthorized URL modifications.
March 18, 2026
CVE-2026-27363: Bakery Autoresponder Addon <= 1.0.6 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-27363 affects the Vc Autoresponder Addon plugin for WordPress (up to version 1.0.6) with a CVSS score of 7.2. This high-severity XSS vulnerability allows unauthenticated attackers to inject scripts. Patching is essential.
March 18, 2026
CVE-2026-27344: Scientific and Interactive Blocks – inseri core <= 1.0.5 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-27344 affects the Inseri Core plugin for WordPress (up to version 1.0.5) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability, so patching is essential.
March 18, 2026
CVE-2026-27362: Bakery Autoresponder Addon <= 1.0.6 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-27362 affects the Vc Autoresponder Addon plugin for WordPress (up to version 1.0.6) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability, so patching is essential.
March 18, 2026
CVE-2026-2301: Post Duplicator <= 3.0.8 Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter PoC, Patch Analysis & Rule
CVE-2026-2301 affects the Post Duplicator plugin (up to version 3.0.8) with a medium severity (CVSS 4.3) vulnerability. Patch to version 3.0.9 to prevent unauthorized meta key insertion by authenticated users.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
