Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-1994: s2Member <= 260127 Unauthenticated Privilege Escalation via Account Takeover PoC, Patch Analysis & Rule

CVE-2026-1994 affects the s2Member plugin for WordPress, allowing unauthenticated attackers to escalate privileges and take over accounts. Update to version 260215 to mitigate this critical vulnerability with a CVSS score of 9.8.
March 18, 2026

CVE-2025-14452: WP Customer Reviews <= 3.7.5 Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter PoC, Patch Analysis & Rule

CVE-2025-14452 affects WP Customer Reviews plugin versions up to 3.7.5, allowing reflected XSS due to poor input sanitization. Upgrade to 3.7.6 to mitigate this high-severity vulnerability with a CVSS score of 7.2.
March 18, 2026

CVE-2025-14851: YaMaps for WordPress <= 0.6.40 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Parameters PoC, Patch Analysis & Rule

CVE-2025-14851 affects the YaMaps plugin (up to version 0.6.40) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should update to the patched version to mitigate risks from authenticated attackers.
March 18, 2026

CVE-2025-4521: IDonate 2.1.5 2.1.9 Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_profile Function PoC, Patch Analysis & Rule

CVE-2025-4521 affects the IDonate plugin (versions 2.1.5 to 2.1.9) with a CVSS score of 8.8. Authenticated users can escalate privileges and take over accounts. Update to version 2.1.0 to mitigate this vulnerability.
March 18, 2026

CVE-2026-0556: XO Event Calendar <= 3.2.10 Authenticated (Contributor+) Stored Cross-Site Scripting via 'xo_event_field' shortcode PoC, Patch Analysis & Rule

CVE-2026-0556 affects the Xo Event Calendar plugin for WordPress (up to version 3.2.10) with a medium severity (CVSS 6.4) XSS vulnerability. Users should update to the patched version to mitigate risks from authenticated attackers.
March 18, 2026

CVE-2025-13930: Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.5 Missing Authorization to Unauthenticated Arbitrary Attachment Deletion PoC, Patch Analysis & Rule

CVE-2025-13930 affects WooCommerce Checkout Manager versions up to 7.8.5, allowing unauthenticated attackers to delete guest order attachments. Upgrade to version 7.8.6 to mitigate this medium severity vulnerability.
March 18, 2026

CVE-2025-14427: Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches <= 21.0.9 Missing Authorization to Authenticated (Subscriber+) Email MFA Update PoC, Patch Analysis & Rule

CVE-2025-14427 affects the Wp Simple Firewall plugin (up to version 21.0.9) with a medium severity (CVSS 4.3) vulnerability. Patch to version 21.0.10 to prevent unauthorized disabling of Email 2FA by authenticated users.
March 18, 2026

CVE-2025-14342: SEO Plugin by Squirrly SEO <= 12.4.14 Missing Authorization to Authenticated (Subscriber+) Cloud Service Disconnection PoC, Patch Analysis & Rule

CVE-2025-14342 affects Squirrly SEO plugin versions up to 12.4.14, allowing authenticated users to disconnect sites from the cloud service. Update to version 12.4.15 to mitigate this medium severity vulnerability.
March 18, 2026

CVE-2025-14270: OneClick Chat to Order <= 1.0.9 Missing Authorization to Authenticated (Editor+) Plugin Settings Update PoC, Patch Analysis & Rule

CVE-2025-14270 affects the OneClick Whatsapp Order plugin (v1.0.9) with a low severity CVSS of 2.7. Authenticated attackers can bypass authorization to alter WhatsApp numbers, redirecting orders. Update to v1.1.0 to mitigate.
March 18, 2026

CVE-2026-2502: xmlrpc attacks blocker <= 1.0 Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' PoC, Patch Analysis & Rule

CVE-2026-2502 affects the Xmlrpc Attacks Blocker plugin (v1.0) with a medium severity (CVSS 6.1) stored XSS vulnerability. Ensure you update to the patched version to mitigate risks associated with unauthorized script execution.
March 18, 2026

CVE-2025-14167: Remove Post Type Slug <= 1.0.2 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

CVE-2025-14167 affects the Remove Post Type Slug plugin for WordPress (up to v1.0.2) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure you update to the patched version to mitigate unauthorized settings changes.
March 18, 2026

CVE-2026-0561: Shield Security <= 21.0.8 Unauthenticated Reflected Cross-Site Scripting via 'message' Parameter PoC, Patch Analysis & Rule

CVE-2026-0561 affects Wp Simple Firewall versions up to 21.0.8, allowing unauthenticated XSS attacks due to insufficient input sanitization. Upgrade to version 21.0.10 to mitigate this medium severity vulnerability.
March 18, 2026

CVE-2026-1044: Tennis Court Bookings <= 1.2.7 Authenticated (Administrator+) Stored Cross-Site Scripting via Admin Settings and Calendar Parameters PoC, Patch Analysis & Rule

CVE-2026-1044 affects the Tennis Court Bookings plugin for WordPress (up to v1.2.7) with a medium severity CVSS score of 4.4. Admins should patch to prevent stored XSS attacks that could compromise user sessions.
March 18, 2026

CVE-2026-1047: salavat counter Plugin <= 0.9.5 Authenticated (Administrator+) Stored Cross-Site Scripting via 'image_url' Parameter PoC, Patch Analysis & Rule

CVE-2026-1047 affects the Salavat Counter plugin (up to v0.9.5) with a CVSS score of 4.4. This medium-severity XSS vulnerability allows authenticated admins to inject scripts. Users should update to the patched version to mitigate risks.
March 18, 2026

CVE-2025-14076: iXML – Google XML sitemap generator <= 0.6 Reflected Cross-Site Scripting via 'iXML_email' Parameter PoC, Patch Analysis & Rule

CVE-2025-14076 affects the iXML plugin for WordPress, allowing reflected XSS due to insufficient input sanitization. Users should update to the patched version to mitigate potential attacks.
March 18, 2026

CVE-2026-1646: Advance Block Extend <= 1.0.4 Authenticated (Contributor+) Stored Cross-Site Scripting via TitleColor Block Attribute PoC, Patch Analysis & Rule

CVE-2026-1646 affects the Advance Block Extend plugin (v1.0.4) with a medium severity CVSS of 6.4. Authenticated attackers can exploit a stored XSS vulnerability, making timely patching essential for security.
March 18, 2026

CVE-2026-1055: TalkJS <= 0.1.15 Authenticated (Administrator+) Stored Cross-Site Scripting via 'welcomeMessage' Parameter PoC, Patch Analysis & Rule

CVE-2026-1055 affects the TalkJS plugin for WordPress (up to 0.1.15) with a medium severity CVSS score of 4.4. Admins should upgrade to 0.1.16 to mitigate stored XSS risks in multi-site environments.
March 18, 2026

CVE-2026-1373: Easy Author Image <= 1.7 Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Picture URL PoC, Patch Analysis & Rule

CVE-2026-1373 affects the Easy Author Image plugin for WordPress (up to v1.7) with a CVSS score of 6.4. Authenticated attackers can exploit stored XSS vulnerabilities, making timely patching essential.
March 18, 2026

CVE-2026-2284: News Element Elementor Blog Magazine <= 1.0.8 Missing Authorization to Authenticated (Subscriber+) Data Loss PoC, Patch Analysis & Rule

CVE-2026-2284 affects the News Element plugin (up to v1.0.8) with a medium severity (CVSS 5.4) vulnerability allowing authenticated attackers to truncate core database tables and delete uploads. Patching is essential to prevent data loss.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works