
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1994: s2Member <= 260127 Unauthenticated Privilege Escalation via Account Takeover PoC, Patch Analysis & Rule
CVE-2026-1994 affects the s2Member plugin for WordPress, allowing unauthenticated attackers to escalate privileges and take over accounts. Update to version 260215 to mitigate this critical vulnerability with a CVSS score of 9.8.
March 18, 2026
CVE-2025-14452: WP Customer Reviews <= 3.7.5 Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter PoC, Patch Analysis & Rule
CVE-2025-14452 affects WP Customer Reviews plugin versions up to 3.7.5, allowing reflected XSS due to poor input sanitization. Upgrade to 3.7.6 to mitigate this high-severity vulnerability with a CVSS score of 7.2.
March 18, 2026
CVE-2025-14851: YaMaps for WordPress <= 0.6.40 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Parameters PoC, Patch Analysis & Rule
CVE-2025-14851 affects the YaMaps plugin (up to version 0.6.40) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should update to the patched version to mitigate risks from authenticated attackers.
March 18, 2026
CVE-2025-4521: IDonate 2.1.5 2.1.9 Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via idonate_donor_profile Function PoC, Patch Analysis & Rule
CVE-2025-4521 affects the IDonate plugin (versions 2.1.5 to 2.1.9) with a CVSS score of 8.8. Authenticated users can escalate privileges and take over accounts. Update to version 2.1.0 to mitigate this vulnerability.
March 18, 2026
CVE-2026-0556: XO Event Calendar <= 3.2.10 Authenticated (Contributor+) Stored Cross-Site Scripting via 'xo_event_field' shortcode PoC, Patch Analysis & Rule
CVE-2026-0556 affects the Xo Event Calendar plugin for WordPress (up to version 3.2.10) with a medium severity (CVSS 6.4) XSS vulnerability. Users should update to the patched version to mitigate risks from authenticated attackers.
March 18, 2026
CVE-2025-13930: Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.5 Missing Authorization to Unauthenticated Arbitrary Attachment Deletion PoC, Patch Analysis & Rule
CVE-2025-13930 affects WooCommerce Checkout Manager versions up to 7.8.5, allowing unauthenticated attackers to delete guest order attachments. Upgrade to version 7.8.6 to mitigate this medium severity vulnerability.
March 18, 2026
CVE-2026-0722: Shield Security <= 21.0.8 Cross-Site Request Forgery to SQL Injection PoC, Patch Analysis & Rule
CVE-2026-0722 affects the Wp Simple Firewall plugin (versions
March 18, 2026
CVE-2025-14427: Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches <= 21.0.9 Missing Authorization to Authenticated (Subscriber+) Email MFA Update PoC, Patch Analysis & Rule
CVE-2025-14427 affects the Wp Simple Firewall plugin (up to version 21.0.9) with a medium severity (CVSS 4.3) vulnerability. Patch to version 21.0.10 to prevent unauthorized disabling of Email 2FA by authenticated users.
March 18, 2026
CVE-2025-14342: SEO Plugin by Squirrly SEO <= 12.4.14 Missing Authorization to Authenticated (Subscriber+) Cloud Service Disconnection PoC, Patch Analysis & Rule
CVE-2025-14342 affects Squirrly SEO plugin versions up to 12.4.14, allowing authenticated users to disconnect sites from the cloud service. Update to version 12.4.15 to mitigate this medium severity vulnerability.
March 18, 2026
CVE-2025-14270: OneClick Chat to Order <= 1.0.9 Missing Authorization to Authenticated (Editor+) Plugin Settings Update PoC, Patch Analysis & Rule
CVE-2025-14270 affects the OneClick Whatsapp Order plugin (v1.0.9) with a low severity CVSS of 2.7. Authenticated attackers can bypass authorization to alter WhatsApp numbers, redirecting orders. Update to v1.1.0 to mitigate.
March 18, 2026
CVE-2026-2502: xmlrpc attacks blocker <= 1.0 Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' PoC, Patch Analysis & Rule
CVE-2026-2502 affects the Xmlrpc Attacks Blocker plugin (v1.0) with a medium severity (CVSS 6.1) stored XSS vulnerability. Ensure you update to the patched version to mitigate risks associated with unauthorized script execution.
March 18, 2026
CVE-2025-14167: Remove Post Type Slug <= 1.0.2 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule
CVE-2025-14167 affects the Remove Post Type Slug plugin for WordPress (up to v1.0.2) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure you update to the patched version to mitigate unauthorized settings changes.
March 18, 2026
CVE-2026-0561: Shield Security <= 21.0.8 Unauthenticated Reflected Cross-Site Scripting via 'message' Parameter PoC, Patch Analysis & Rule
CVE-2026-0561 affects Wp Simple Firewall versions up to 21.0.8, allowing unauthenticated XSS attacks due to insufficient input sanitization. Upgrade to version 21.0.10 to mitigate this medium severity vulnerability.
March 18, 2026
CVE-2026-1044: Tennis Court Bookings <= 1.2.7 Authenticated (Administrator+) Stored Cross-Site Scripting via Admin Settings and Calendar Parameters PoC, Patch Analysis & Rule
CVE-2026-1044 affects the Tennis Court Bookings plugin for WordPress (up to v1.2.7) with a medium severity CVSS score of 4.4. Admins should patch to prevent stored XSS attacks that could compromise user sessions.
March 18, 2026
CVE-2026-1047: salavat counter Plugin <= 0.9.5 Authenticated (Administrator+) Stored Cross-Site Scripting via 'image_url' Parameter PoC, Patch Analysis & Rule
CVE-2026-1047 affects the Salavat Counter plugin (up to v0.9.5) with a CVSS score of 4.4. This medium-severity XSS vulnerability allows authenticated admins to inject scripts. Users should update to the patched version to mitigate risks.
March 18, 2026
CVE-2025-14076: iXML – Google XML sitemap generator <= 0.6 Reflected Cross-Site Scripting via 'iXML_email' Parameter PoC, Patch Analysis & Rule
CVE-2025-14076 affects the iXML plugin for WordPress, allowing reflected XSS due to insufficient input sanitization. Users should update to the patched version to mitigate potential attacks.
March 18, 2026
CVE-2026-1646: Advance Block Extend <= 1.0.4 Authenticated (Contributor+) Stored Cross-Site Scripting via TitleColor Block Attribute PoC, Patch Analysis & Rule
CVE-2026-1646 affects the Advance Block Extend plugin (v1.0.4) with a medium severity CVSS of 6.4. Authenticated attackers can exploit a stored XSS vulnerability, making timely patching essential for security.
March 18, 2026
CVE-2026-1055: TalkJS <= 0.1.15 Authenticated (Administrator+) Stored Cross-Site Scripting via 'welcomeMessage' Parameter PoC, Patch Analysis & Rule
CVE-2026-1055 affects the TalkJS plugin for WordPress (up to 0.1.15) with a medium severity CVSS score of 4.4. Admins should upgrade to 0.1.16 to mitigate stored XSS risks in multi-site environments.
March 18, 2026
CVE-2026-1373: Easy Author Image <= 1.7 Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Picture URL PoC, Patch Analysis & Rule
CVE-2026-1373 affects the Easy Author Image plugin for WordPress (up to v1.7) with a CVSS score of 6.4. Authenticated attackers can exploit stored XSS vulnerabilities, making timely patching essential.
March 18, 2026
CVE-2026-2284: News Element Elementor Blog Magazine <= 1.0.8 Missing Authorization to Authenticated (Subscriber+) Data Loss PoC, Patch Analysis & Rule
CVE-2026-2284 affects the News Element plugin (up to v1.0.8) with a medium severity (CVSS 5.4) vulnerability allowing authenticated attackers to truncate core database tables and delete uploads. Patching is essential to prevent data loss.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
