Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-1405: Slider Future <= 1.0.5 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule

CVE-2026-1405 affects the Slider Future plugin (v1.0.5 and earlier) with a critical CVSS score of 9.8 due to an unauthenticated file upload vulnerability. Users should update to the patched version to mitigate potential remote code...
March 18, 2026

CVE-2026-2504: Dealia – Request a quote <= 1.0.7 Missing Authorization to Authenticated (Contributor+) Plugin Configuration Reset PoC, Patch Analysis & Rule

CVE-2026-2504 affects the Dealia Request A Quote plugin (v1.0.7) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized data modification. Upgrade to v1.0.8 to mitigate risks from authenticated attackers.
March 18, 2026

CVE-2026-0912: Toret Manager <= 1.2.7 Authenticated (Subscriber+) Arbitrary Options Update via AJAX actions PoC, Patch Analysis & Rule

CVE-2026-0912 affects the Toret Manager plugin (up to 1.2.7) with a high severity CVSS score of 8.8. It allows authenticated users to escalate privileges by modifying site options, making immediate patching essential.
March 18, 2026

CVE-2026-0926: Prodigy Commerce <= 3.3.0 Unauthenticated Local File Inclusion via parameters[template_name] PoC, Patch Analysis & Rule

CVE-2026-0926 affects Prodigy Commerce plugin versions up to 3.3.0, allowing unauthenticated local file inclusion with a CVSS score of 9.8. Upgrade to version 3.3.1 to mitigate this critical vulnerability.
March 18, 2026

CVE-2026-2282: Slidorion <= 1.0.2 Authenticated (Administrator+) Stored Cross-Site Scripting via Slidorion Settings PoC, Patch Analysis & Rule

CVE-2026-2282 affects the Slidorion WordPress plugin (up to v1.0.2) with a medium severity CVSS score of 4.4. Authenticated attackers can exploit this stored XSS vulnerability, so ensure timely patching or WAF coverage.
March 18, 2026

CVE-2025-13563: Lizza LMS Pro <= 1.0.3 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule

CVE-2025-13563 affects the Lizza LMS Pro plugin for WordPress, allowing unauthenticated users to gain admin access. With a CVSS score of 9.8, it's critical to update from version 1.0.3 to mitigate this privilege escalation risk.
March 18, 2026

CVE-2026-1455: Whatsiplus Scheduled Notification for Woocommerce <= 1.0.1 Cross-Site Request Forgery to 'wsnfw_save_users_settings' AJAX Action PoC, Patch Analysis & Rule

CVE-2026-1455 affects the Whatsiplus Scheduled Notification for Woocommerce plugin (up to v1.0.1) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure you patch to the latest version to mitigate unauthorized configuration changes.
March 18, 2026

CVE-2026-0974: Orderable <= 1.20.0 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation PoC, Patch Analysis & Rule

CVE-2026-0974 affects the Orderable plugin (up to v1.20.0) with a CVSS score of 8.8. It allows authenticated users to install arbitrary plugins, risking remote code execution. Update to v1.20.1 to mitigate this vulnerability.
March 18, 2026

CVE-2026-1043: PostmarkApp Email Integrator <= 2.4 Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings PoC, Patch Analysis & Rule

CVE-2026-1043 affects the Postmarkapp Email Integrator plugin for WordPress (up to version 2.4) with a medium severity (CVSS 4.4) due to stored XSS. Admins should update to the patched version to mitigate risks.
March 18, 2026

CVE-2025-13413: Country Blocker for AdSense <= 1.0 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

CVE-2025-13413 affects the Country Blocker For Adsense plugin (v1.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure nonce validation is implemented to mitigate the risk of unauthorized settings changes.
March 18, 2026

CVE-2025-13864: Breeze – WordPress Cache Plugin <= 2.2.21 Missing Authorization to Cache Deletion PoC, Patch Analysis & Rule

CVE-2025-13864 affects the Breeze plugin (up to version 2.2.21) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized cache clearing. Upgrade to version 2.2.22 to mitigate this risk.
March 18, 2026

CVE-2025-13438: Page Title, Description & Open Graph Updater <= 1.02 Cross-Site Request Forgery to Arbitrary Page Title Modification PoC, Patch Analysis & Rule

CVE-2025-13438 affects the Page Title Description Open Graph Updater plugin (up to v1.02) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure to patch to prevent unauthorized metadata changes.
March 18, 2026

CVE-2025-13617: Apollo13 Framework Extension <= 1.9.8 Authenticated (Contributor+) Stored Cross-Site Scripting via `a13_alt_link` Parameter PoC, Patch Analysis & Rule

CVE-2025-13617 affects the Apollo13 Framework Extensions plugin for WordPress (up to version 1.9.8) with a medium severity CVSS score of 6.4. Ensure you update to the patched version to mitigate the risk of stored XSS attacks.
March 18, 2026

CVE-2025-13603: WP AUDIO GALLERY <= 2.0 Authenticated (Subscriber+) Arbitrary File Read via .htaccess Manipulation PoC, Patch Analysis & Rule

CVE-2025-13603 affects the WP Audio Gallery plugin (up to v2.0) with a CVSS score of 8.8. It allows authenticated attackers to overwrite the .htaccess file, risking server file exposure. Patching is essential for security.
March 18, 2026

CVE-2025-12975: CTX Feed – WooCommerce Product Feed Manager <= 6.6.11 Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation PoC, Patch Analysis & Rule

CVE-2025-12975 affects the Webappick Product Feed For Woocommerce plugin (up to v6.6.11) with a CVSS of 7.2. This high-severity remote code execution vulnerability allows authenticated attackers to install arbitrary plugins. Update to...
March 18, 2026

CVE-2025-12884: Advanced Ads – Ad Manager & AdSense <= 2.0.14 Missing Authorization to Authenticated (Subscriber+) Ad Placements Update PoC, Patch Analysis & Rule

CVE-2025-12884 affects the Advanced Ads plugin (up to 2.0.14) with a CVSS score of 4.3. This medium severity vulnerability allows authenticated users to bypass authorization and alter ad placements. Update to 2.0.15 to mitigate.
March 18, 2026

CVE-2025-12500: Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.1 Unauthenticated Limited File Upload PoC, Patch Analysis & Rule

CVE-2025-12500 affects WooCommerce Checkout Manager (up to 7.8.1) with a medium severity (CVSS 5.3) file upload vulnerability. Update to version 7.8.2 to mitigate the risk of unauthenticated file uploads.
March 18, 2026

CVE-2025-13587: Two Factor (2FA) Authentication via Email <= 1.9.8 Two-Factor Authentication Bypass via token PoC, Patch Analysis & Rule

CVE-2025-13587 affects the Two Factor 2fa Via Email plugin (up to version 1.9.8) with a medium severity (CVSS 6.5) authentication bypass vulnerability. Update to version 1.9.9 to mitigate risks.
March 18, 2026

CVE-2025-12882: Clasifico Listing <= 2.0 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule

CVE-2025-12882 affects the Clasifico Listing plugin for WordPress (up to version 2.0) with a critical CVSS score of 9.8. Unauthenticated users can escalate privileges by manipulating account registration. Immediate patching is essential.
March 18, 2026

CVE-2025-12375: Printful Integration for WooCommerce <= 2.2.11 Authenticated (Contributor+) Server-Side Request Forgery PoC, Patch Analysis & Rule

CVE-2025-12375 affects the Printful Shipping For WooCommerce plugin (up to v2.2.11) with a medium severity (CVSS 6.4) SSRF vulnerability. Users should upgrade to v2.2.12 to mitigate potential remote code execution risks.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works