Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-27406: My Tickets – Accessible Event Ticketing <= 2.1.0 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

CVE-2026-27406 affects the My Tickets plugin for WordPress (up to v2.1.0) with a medium severity CVSS score of 5.3. Unauthenticated users can access sensitive data; update to v2.1.1 to mitigate this risk.
March 18, 2026

CVE-2026-27411: SiteGuard WP Plugin <= 1.7.9 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-27411 affects SiteGuard plugin versions up to 1.7.9, allowing unauthorized access due to a missing capability check. Users should patch to mitigate this medium severity vulnerability.
March 18, 2026

CVE-2026-27388: DesignThemes Booking Manager <= 2.0 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-27388 affects the DesignThemes Booking Manager plugin (up to version 2.0) with a CVSS score of 5.3. Unauthenticated attackers can exploit this medium-severity flaw, making patching essential for security.
March 18, 2026

CVE-2026-2385: The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 Unauthenticated Email Relay PoC, Patch Analysis & Rule

CVE-2026-2385 affects The Plus Addons For Elementor Page Builder (up to 6.4.7) with a CVSS score of 5.3. It allows unauthenticated email relay and redirection. Update to version 6.4.8 to mitigate this vulnerability.
March 18, 2026

CVE-2026-27386: DesignThemes Directory Addon <= 1.8 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-27386 affects the DesignThemes Directory Addon plugin for WordPress (up to version 1.8) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Users should update to the patched version to mitigate risks.
March 18, 2026

CVE-2025-14339: weMail <= 2.0.7 Missing Authorization to Unauthenticated Form Deletion PoC, Patch Analysis & Rule

CVE-2025-14339 affects the weMail plugin (up to v2.0.7) with a medium severity score of 6.5. Unauthenticated users can delete forms due to insufficient permission checks. Upgrade to v2.0.8 to mitigate this risk.
March 18, 2026

CVE-2026-25388: Ads Pro <= 5.0 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-25388 affects the Ap Plugin Scripteo (versions up to 5.0) with a medium severity CVSS score of 4.3. Authenticated users can exploit this vulnerability for unauthorized actions. Ensure you update to the patched version.
March 18, 2026

CVE-2026-27542: Woocommerce Wholesale Lead Capture <= 2.0.3.1 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule

CVE-2026-27542 affects the WooCommerce Wholesale Lead Capture plugin (up to version 2.0.3.1) with a critical CVSS score of 9.8. Unauthenticated attackers can escalate privileges to administrator level. Patch immediately.
March 18, 2026

CVE-2026-27540: Woocommerce Wholesale Lead Capture <= 2.0.3.1 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule

CVE-2026-27540 affects the WooCommerce Wholesale Lead Capture plugin (up to 2.0.3.1) with a critical CVSS score of 9.8. Unauthenticated attackers can exploit a file upload vulnerability, so patching is essential.
March 18, 2026

CVE-2026-25386: Ally <= 4.0.2 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-25386 affects the Pojo Accessibility plugin (versions
March 18, 2026

CVE-2026-2384: Quiz Maker <= 6.7.1.7 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode PoC, Patch Analysis & Rule

CVE-2026-2384 affects the Quiz Maker plugin for WordPress (up to 6.7.1.7) with a medium severity (CVSS 6.4) XSS vulnerability. Update to version 6.7.1.8 to mitigate risks from authenticated attackers.
March 18, 2026

CVE-2026-2486: Master Addons For Elementor <= 2.1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'ma_el_bh_table_btn_text' PoC, Patch Analysis & Rule

CVE-2026-2486 affects the Master Addons plugin for WordPress (up to 2.1.1) with a medium severity CVSS of 6.4. Ensure you update to version 2.1.2 to mitigate the stored XSS risk from authenticated users.
March 18, 2026

CVE-2026-27541: Wholesale Suite <= 2.2.6 Authenticated (Shop Manager) Privilege Escalation PoC, Patch Analysis & Rule

CVE-2026-27541 affects the WooCommerce Wholesale Prices plugin (up to v2.2.6) with a CVSS score of 7.2. Authenticated users can escalate privileges to admin. Update to v2.2.7 to mitigate this high-severity remote code execution risk.
March 18, 2026

CVE-2026-25389: EventPrime <= 4.2.8.3 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

CVE-2026-25389 affects the Eventprime Event Calendar Management plugin (up to version 4.2.8.3) with a medium severity (CVSS 5.3) vulnerability allowing unauthenticated data exposure. Update to version 4.2.8.4 to mitigate risks.
March 18, 2026

CVE-2026-25387: Image Optimizer by Elementor <= 1.7.1 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-25387 affects the Image Optimization plugin for WordPress (up to 1.7.1) with a CVSS score of 4.3. Update to version 1.7.2 to mitigate unauthorized access risks from authenticated attackers.
March 18, 2026

CVE-2026-25378: Nelio AB Testing <= 8.2.4 Authenticated (Editor+) SQL Injection PoC, Patch Analysis & Rule

CVE-2026-25378 affects the Nelio AB Testing plugin for WordPress, with a medium severity CVSS score of 4.9. Users should update to version 8.2.5 to mitigate the SQL injection risk that could expose sensitive data.
March 18, 2026

CVE-2026-25384: WP-Lister Lite for eBay <= 3.8.5 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-25384 affects WP Lister For eBay versions up to 3.8.5, allowing unauthorized access due to a missing capability check. Users should update to the patched version to mitigate this medium severity vulnerability.
March 18, 2026

CVE-2026-25385: URL Shortify <= 1.12.3 Authenticated (Author+) Server-Side Request Forgery PoC, Patch Analysis & Rule

CVE-2026-25385 affects the URL Shortify plugin (up to version 1.12.3) with a medium severity (CVSS 6.4) SSRF vulnerability. Update to version 1.12.4 to mitigate the risk of unauthorized web requests from your WordPress site.
March 18, 2026

CVE-2026-2718: Dealia <= 1.0.8 Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block Attributes PoC, Patch Analysis & Rule

CVE-2026-2718 reveals a medium severity XSS vulnerability in the Dealia Request A Quote plugin for WordPress, affecting versions up to 1.0.8. Patching is essential to prevent authenticated attacks that can inject malicious scripts.
March 18, 2026

CVE-2026-2716: Client Testimonial Slider <= 2.0 Authenticated (Administrator+) Stored Cross-Site Scripting via 'Testimonial Heading' Setting PoC, Patch Analysis & Rule

CVE-2026-2716 affects the Wp Client Testimonial plugin (up to v2.0) with a medium severity CVSS score of 4.4 due to stored XSS. Admins should patch to mitigate risks of script injection in multi-site setups.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works