
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1893: Orbisius Random Name Generator <= 1.0.2 Authenticated (Contributor+) Stored Cross-Site Scripting via 'btn_label' Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-1893 in Orbisius Random Name Generator (CVSS 6.4): Orbisius Random Name Generator. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.0.3.
March 18, 2026
CVE-2026-0910: wpForo Forum <= 2.4.13 Authenticated (Subscriber+) PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-0910 in Wpforo (CVSS 8.8): wpForo Forum. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.4.14.
March 18, 2026
CVE-2025-14541: Lucky Wheel Giveaway <= 1.0.22 Authenticated (Administrator+) Remote Code Execution via 'conditional_tags' Parameter PoC, Patch Analysis & Rule
High CVE-2025-14541 in Wp Lucky Wheel (CVSS 7.2): Lucky Wheel Giveaway. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-13391: Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) <= 4.9.60 Missing Authorization to Unauthenticated Arbitrary Attachment and Dropbox File Deletion PoC, Patch Analysis & Rule
Medium CVE-2025-13391 in Uni Woo Custom Product Options Premium (CVSS 5.8): Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium). Atomic Edge summarizes impact, exploitability, and patch details, with WAF...
March 18, 2026
CVE-2026-25423: Real 3D FlipBook <= 4.19.1 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-25423 in Real3d Flipbook Lite (CVSS 4.3): Real 3D FlipBook. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.19.2.
March 18, 2026
CVE-2025-68552: WooCommerce Coming Soon Product with Countdown <= 5.0 Authenticated (Subscriber+) Local File Inclusion PoC, Patch Analysis & Rule
High CVE-2025-68552 in Woo Coming Soon Product (CVSS 7.5): WooCommerce Coming Soon Product with Countdown. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-67998: Miraculous Elementor <= 2.0.7 Authenticated (Subscriber+) Privilege Escalation PoC, Patch Analysis & Rule
High CVE-2025-67998 in Miraculous El (CVSS 8.8): Miraculous Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-69390: Business Template Blocks for WPBakery (Visual Composer) Page Builder <= 1.3.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-69390 in Templates And Addons For Wpbakery Page Builder (CVSS 6.1): Business Template Blocks for WPBakery (Visual Composer) Page Builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
March 18, 2026
CVE-2025-69389: Visitor Maps Extended Referer Field <= 1.2.6 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-69389 in Visitor Maps Extended Referer Field (CVSS 6.1): Visitor Maps Extended Referer Field. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.2.3.
March 18, 2026
CVE-2026-1560: Custom Block Builder – Lazy Blocks <= 4.2.0 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule
High CVE-2026-1560 in Lazy Blocks (CVSS 8.8): Custom Block Builder – Lazy Blocks. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.2.1.
March 18, 2026
CVE-2026-1866: Name Directory <= 1.32.0 Unauthenticated Stored Cross-Site Scripting via Double HTML-Entity Encoding in Submission Form PoC, Patch Analysis & Rule
High CVE-2026-1866 in Name Directory (CVSS 7.2): Name Directory. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.32.1.
March 18, 2026
CVE-2026-2268: Ninja Forms <= 3.14.0 Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action PoC, Patch Analysis & Rule
High CVE-2026-2268 in Ninja Forms (CVSS 7.5): Ninja Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.14.1.
March 18, 2026
CVE-2026-1922: The Events Calendar Shortcode & Block <= 3.1.2 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
Medium CVE-2026-1922 in The Events Calendar Shortcode (CVSS 6.4): The Events Calendar Shortcode & Block. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.1.3.
March 18, 2026
CVE-2025-14895: PopupKit <= 2.2.0 Missing Authorization to Sensitive Information Disclosure and Data Deletion PoC, Patch Analysis & Rule
Medium CVE-2025-14895 in Popup Builder Block (CVSS 5.4): PopupKit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.2.1.
March 18, 2026
CVE-2026-1722: WCFM Marketplace <= 3.7.0 Insecure Direct Object Reference to Unauthenticated Arbitrary Refund Request Creation PoC, Patch Analysis & Rule
Medium CVE-2026-1722 in Wc Multivendor Marketplace (CVSS 5.3): WCFM Marketplace. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.7.1.
March 18, 2026
CVE-2025-69328: Booking and Rental Manager <= 2.5.9 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2025-69328 in Booking And Rental Manager For Woocommerce (CVSS 7.5): Booking and Rental Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-15147: WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 Insecure Direct Object Reference to Update Membership Payment PoC, Patch Analysis & Rule
Medium CVE-2025-15147 in Wc Multivendor Membership (CVSS 4.3): WCFM Membership – WooCommerce Memberships for Multivendor Marketplace. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to...
March 18, 2026
CVE-2026-0845: WCFM WooCommerce Frontend Manager <= 6.7.24 Authenticated (Shop Manager+) Arbitrary Options Update PoC, Patch Analysis & Rule
High CVE-2026-0845 in Wc Frontend Manager (CVSS 7.2): WCFM - WooCommerce Frontend Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 6.7.25.
March 18, 2026
CVE-2025-69326: NEX-Forms <= 9.1.7 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-69326 in Nex Forms Express Wp Form Builder (CVSS 6.1): NEX-Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 9.1.8.
March 18, 2026
CVE-2025-67994: YayCurrency <= 3.3 Missing Authorization to Unauthenticated Arbitrary Post Deletion PoC, Patch Analysis & Rule
Medium CVE-2025-67994 in Yaycurrency (CVSS 5.3): YayCurrency. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.3.1.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
