Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2025-14742: WP Recipe Maker <= 10.2.3 Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure PoC, Patch Analysis & Rule

CVE-2025-14742 affects the WP Recipe Maker plugin (up to version 10.2.3) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized access to sensitive recipe data. Upgrade to version 10.3.0 to mitigate this risk.
March 18, 2026

CVE-2026-2367: Secure Copy Content Protection and Content Locking <= 5.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-2367 affects the Secure Copy Content Protection plugin (up to 5.0.1) with a medium severity (CVSS 6.4) XSS vulnerability. Update to version 5.0.2 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026

CVE-2026-1929: Advanced Woo Labels <= 2.37 Authenticated (Contributor+) Remote Code Execution via 'callback' Parameter PoC, Patch Analysis & Rule

CVE-2026-1929 affects the Advanced Woo Labels plugin (up to v2.36) with a CVSS score of 8.8. This high-severity remote code execution flaw allows authenticated users to execute arbitrary commands. Upgrade to v2.37 to mitigate.
March 18, 2026

CVE-2026-2416: Geo Mashup <= 1.13.17 Unauthenticated SQL Injection via 'sort' Parameter PoC, Patch Analysis & Rule

The Geo Mashup plugin for WordPress, versions up to 1.13.17, has a high-severity SQL injection vulnerability (CVE-2026-2416) due to insufficient input validation. Update to version 1.13.18 to mitigate risks.
March 18, 2026

CVE-2026-1614: Rise Blocks – A Complete Gutenberg Page Builder <= 3.7 Authenticated (Contributor+) Stored Cross-Site Scripting via Site Identity Block Attributes PoC, Patch Analysis & Rule

CVE-2026-1614 affects the Rise Blocks plugin (up to v3.7) with a CVSS score of 6.4. Authenticated attackers can exploit stored XSS via the 'logoTag' attribute. Users should update to the patched version to mitigate risks.
March 18, 2026

CVE-2026-1916: WPGSI: Spreadsheet Integration <= 3.8.3 Missing Authorization to Unauthenticated Arbitrary Post Creation and Deletion via Forged Base64 Token PoC, Patch Analysis & Rule

CVE-2026-1916 affects the WPGSI: Spreadsheet Integration plugin (up to version 3.8.3) with a high severity CVSS score of 7.5. Patching to version 3.8.4 is crucial to prevent unauthorized data modification.
March 18, 2026

CVE-2026-2479: Responsive Lightbox & Gallery <= 2.7.1 Authenticated (Author+) Server-Side Request Forgery via Remote Library Image Upload PoC, Patch Analysis & Rule

CVE-2026-2479 affects the Responsive Lightbox plugin (up to 2.7.1) with a medium severity (CVSS 5.0) SSRF vulnerability. Update to version 2.7.2 to mitigate risks from authenticated attackers exploiting this flaw.
March 18, 2026

CVE-2026-27379: NextScripts: Social Networks Auto-Poster <= 4.4.7 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule

CVE-2026-27379 affects the NextScripts Social Networks Auto-Poster plugin (up to version 4.4.7) with a CVSS score of 7.5. Authenticated attackers can exploit this file upload vulnerability to inject PHP objects, risking data deletion...
March 18, 2026

CVE-2026-27374: WooCommerce Order Details <= 3.1 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-27374 affects the WooCommerce Order Details plugin (up to v3.1) with a medium severity score of 5.3. Unauthenticated attackers can exploit this remote code execution flaw, so ensure you update to the patched version.
March 18, 2026

CVE-2026-27373: Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.2.3 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule

CVE-2026-27373 affects the Tablesome plugin (up to version 1.2.3) with a medium severity CVSS score of 6.5. Authenticated users can exploit an SQL injection vulnerability, emphasizing the need for immediate patching.
March 18, 2026

CVE-2026-27370: Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.5.1 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

CVE-2026-27370 affects the Chaty plugin for WordPress (up to version 3.5.1) with a CVSS score of 5.3. Unauthenticated attackers can access sensitive data; update to version 3.5.2 to mitigate this risk.
March 18, 2026

CVE-2026-27384: W3 Total Cache <= 2.9.1 Unauthenticated Arbitrary Code Execution PoC, Patch Analysis & Rule

CVE-2026-27384 affects W3 Total Cache plugin (up to 2.9.1) with a critical CVSS score of 9.8. Unauthenticated remote code execution allows attackers to execute arbitrary code. Update to version 2.9.2 to mitigate this risk.
March 18, 2026

CVE-2026-27385: DesignThemes Portfolio <= 1.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-27385 affects the DesignThemes Portfolio plugin (up to version 1.3) with a medium severity CVSS score of 6.1. Users should update to the patched version to mitigate the reflected XSS risk.
March 18, 2026

CVE-2026-23546: Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.3.4 Authenticated (Subscriber+) Sensitive Data Exposure PoC, Patch Analysis & Rule

CVE-2026-23546 affects the Classified Listing plugin for WordPress (up to version 5.3.4) with a CVSS score of 4.3. Authenticated users can exploit this medium-severity vulnerability to access sensitive data. Update to version 5.3.5.
March 18, 2026

CVE-2026-27397: Really Simple Security Pro <= 9.5.4.0 Authenticated (Subscriber+) Insecure Direct Object Reference PoC, Patch Analysis & Rule

CVE-2026-27397 affects the Really Simple SSL Pro plugin for WordPress, with a medium severity CVSS score of 4.3. Users should update from version 9.5.4.0 to mitigate unauthorized actions by authenticated attackers.
March 18, 2026

CVE-2026-27428: Eagle Booking <= 1.3.4.3 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule

CVE-2026-27428 affects the Eagle Booking plugin (up to 1.3.4.3) with a medium severity (CVSS 6.5) SQL injection vulnerability. Authenticated attackers can exploit this flaw to extract sensitive data; patching is essential.
March 18, 2026

CVE-2026-27396: Directory Pro <= 2.5.6 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-27396 affects the Directory Pro plugin (up to v2.5.6) with a CVSS score of 5.3. Unauthenticated attackers can exploit this medium-severity flaw, so ensure you update to the patched version to mitigate risks.
March 18, 2026

CVE-2026-27389: WeDesignTech Ultimate Booking Addon <= 1.0.1 Authentication Bypass PoC, Patch Analysis & Rule

CVE-2026-27389 is a critical authentication bypass vulnerability in the WeDesignTech Ultimate Booking Addon for WordPress, with a CVSS score of 9.8. Users should update to the patched version to mitigate unauthorized access risks.
March 18, 2026

CVE-2026-27390: WeDesignTech Ultimate Booking Addon <= 1.0.1 Authenticated (Subscriber+) Authentication Bypass PoC, Patch Analysis & Rule

CVE-2026-27390 affects the WeDesignTech Ultimate Booking Addon for WordPress, allowing authenticated attackers to bypass authentication. Update to version 1.0.2 to mitigate this high-severity vulnerability (CVSS 8.8).
March 18, 2026

CVE-2026-27413: Profile Builder Pro <= 3.13.9 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2026-27413 affects the Profile Builder Pro plugin (up to v3.13.9) with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows attackers to extract sensitive data. Users should patch immediately.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works