
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-22350: PDF for Elementor Forms + Drag And Drop Template Builder <= 6.3.1 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-22350 in Pdf For Elementor Forms (CVSS 4.3): PDF for Elementor Forms + Drag And Drop Template Builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 6.5.0.
March 18, 2026
CVE-2025-15400: OpenPix <= 2.13.3 Missing Authorization to Authenticated (Subscriber+) Settings Update PoC, Patch Analysis & Rule
Medium CVE-2025-15400 in Openpix For Woocommerce (CVSS 4.3): OpenPix. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.13.4.
March 18, 2026
CVE-2026-24956: Download Manager Addons for Elementor <= 1.3.0 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
High CVE-2026-24956 in Wpdm Elementor (CVSS 7.5): Download Manager Addons for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-22346: Slider Responsive Slideshow – Image slider, Gallery slideshow <= 1.5.4 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-22346 in Slider Responsive Slideshow (CVSS 7.5): Slider Responsive Slideshow – Image slider, Gallery slideshow. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1104: FastDup – Fastest WordPress Migration & Duplicator <= 2.7.1 Missing Authorization to Authenticated (Contributor+) Backup Creation and Download PoC, Patch Analysis & Rule
High CVE-2026-1104 in Fastdup (CVSS 8.8): FastDup – Fastest WordPress Migration & Duplicator. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.7.2.
March 18, 2026
CVE-2025-69401: WooODT Lite <= 2.5.2 Unauthenticated Payment Bypass PoC, Patch Analysis & Rule
Medium CVE-2025-69401 in Byconsole Woo Order Delivery Time (CVSS 5.3): WooODT Lite. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-69392: iMoney <= 0.36 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-69392 in Imoney (CVSS 6.1): iMoney. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-69403: Bravis Addons <= 1.1.9 Authenticated (Subscriber+) Arbitrary File Upload PoC, Patch Analysis & Rule
High CVE-2025-69403 in Bravis Addons (CVSS 8.8): Bravis Addons. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-68526: Modal Popup Box <= 1.6.1 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2025-68526 in Modal Popup Box (CVSS 7.5): Modal Popup Box. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.6.2.
March 18, 2026
CVE-2026-2295: WPZOOM Addons for Elementor – Starter Templates & Widgets <= 1.3.2 Unauthenticated Protected Post Exposure via ajax_post_grid_load_more PoC, Patch Analysis & Rule
Medium CVE-2026-2295 in Wpzoom Elementor Addons (CVSS 5.3): WPZOOM Addons for Elementor – Starter Templates & Widgets. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.3.3.
March 18, 2026
CVE-2025-15096: Videospirecore Theme Plugin <= 1.0.6 Authenticated (Subscriber+) Privilege Escalation via User Email Change/Account Takeover PoC, Patch Analysis & Rule
High CVE-2025-15096 in Videospirecore (CVSS 8.8): Videospirecore Theme Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-22345: Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery <= 1.6.0 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-22345 in New Image Gallery (CVSS 7.5): Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.6.1.
March 18, 2026
CVE-2026-1853: BuddyHolis ListSearch <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'placeholder' Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-1853 in Listsearch (CVSS 6.4): BuddyHolis ListSearch. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1748: Invoct – PDF Invoices & Billing for WooCommerce <= 1.6 Missing Authorization to Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2026-1748 in Kirilkirkov Pdf Invoice Manager (CVSS 4.3): Invoct – PDF Invoices & Billing for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.7.
March 18, 2026
CVE-2026-1804: WDES Responsive Popup <= 1.3.6 Authenticated (Contributor+) Stored Cross-Site Scripting via 'attr' Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-1804 in Wdes Responsive Popup (CVSS 6.4): WDES Responsive Popup. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1827: IDE Micro code-editor <= 1.0.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-1827 in Flask Micro (CVSS 6.4): IDE Micro code-editor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1215: MMA Call Tracking <= 2.3.15 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule
Medium CVE-2026-1215 in Mma Call Tracking (CVSS 4.3): MMA Call Tracking. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-0724: WPlyr Media Block <= 1.3.0 Authenticated (Administrator+) Stored Cross-Site Scripting via '_wplyr_accent_color' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-0724 in Wplyr Media Block (CVSS 4.4): WPlyr Media Block. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-15440: iONE360 configurator <= 2.0.57 Unauthenticated Stored Cross-Site Scripting via Contact Form Parameters PoC, Patch Analysis & Rule
High CVE-2025-15440 in Ione360 Configurator (CVSS 7.2): iONE360 configurator. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1885: Slideshow Wp <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'sswp-slide' Shortcode 'sswpid' Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-1885 in Slideshow Wp (CVSS 6.4): Slideshow Wp. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
