
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-3657: My Sticky Bar <= 2.8.6 Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action PoC, Patch Analysis & Rule
High CVE-2026-3657 in Mystickymenu (CVSS 7.5): My Sticky Bar. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.8.7.
March 18, 2026
CVE-2026-1708: Appointment Booking Calendar <= 1.6.9.27 Unauthenticated SQL Injection via 'append_where_sql' Parameter PoC, Patch Analysis & Rule
High CVE-2026-1708 in Simply Schedule Appointments (CVSS 7.5): Appointment Booking Calendar. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.6.9.29.
March 18, 2026
CVE-2026-3231: Checkout Field Editor (Checkout Manager) for WooCommerce <= 2.1.7 Unauthenticated Stored Cross-Site Scripting via Block Checkout Custom Radio Field PoC, Patch Analysis & Rule
High CVE-2026-3231 in Woo Checkout Field Editor Pro (CVSS 7.2): Checkout Field Editor (Checkout Manager) for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.8.
March 18, 2026
CVE-2026-3492: Gravity Forms <= 2.9.28.1 Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title PoC, Patch Analysis & Rule
Medium CVE-2026-3492 in Gravityforms (CVSS 6.4): Gravity Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1993: ExactMetrics 7.1.0 9.0.2 Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update PoC, Patch Analysis & Rule
High CVE-2026-1993 in Google Analytics Dashboard For Wp (CVSS 8.8): ExactMetrics 7.1.0 - 9.0.2 - Authenticated (Custom) Improper Privilege Management to Role Privilege.... Atomic Edge summarizes impact, exploitability, and patch...
March 18, 2026
CVE-2026-3226: LearnPress <= 4.3.2.8 Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering PoC, Patch Analysis & Rule
Medium CVE-2026-3226 in Learnpress (CVSS 4.3): LearnPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.3.3.
March 18, 2026
CVE-2026-2466: DukaPress <= 3.2.4 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2026-2466 in Dukapress (CVSS 7.2): DukaPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-1992: ExactMetrics 8.6.0 9.0.2 Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation PoC, Patch Analysis & Rule
High CVE-2026-1992 in Google Analytics Dashboard For Wp (CVSS 8.8): ExactMetrics 8.6.0 - 9.0.2 - Authenticated (Custom) Insecure Direct Object Reference to Arbitrary.... Atomic Edge summarizes impact, exploitability, and patch details...
March 18, 2026
CVE-2026-2917: Happy Addons for Elementor <= 3.21.0 Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-2917 in Happy Elementor Addons (CVSS 5.4): Happy Addons for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.21.1.
March 18, 2026
CVE-2026-3496: JetBooking <= 4.0.3 Unauthenticated SQL Injection via 'check_in_date' Parameter PoC, Patch Analysis & Rule
High CVE-2026-3496 in Jet Booking (CVSS 7.5): JetBooking. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-3222: WP Maps <= 4.9.1 Unauthenticated SQL Injection via 'location_id' Parameter PoC, Patch Analysis & Rule
High CVE-2026-3222 in Wp Google Map Plugin (CVSS 7.5): WP Maps. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.9.2.
March 18, 2026
CVE-2026-2918: Happy Addons for Elementor <= 3.21.0 Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions PoC, Patch Analysis & Rule
Medium CVE-2026-2918 in Happy Elementor Addons (CVSS 6.4): Happy Addons for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.21.1.
March 18, 2026
CVE-2026-2358: WP ULike <= 5.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-2358 in Wp Ulike (CVSS 6.4): WP ULike. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.0.2.
March 18, 2026
CVE-2025-12473: RTMKit <= 1.6.8 Reflected Cross-Site Scripting via 'themebuilder' Parameter PoC, Patch Analysis & Rule
Medium CVE-2025-12473 in Rometheme For Elementor (CVSS 6.1): RTMKit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.0.0.
March 18, 2026
CVE-2026-2413: Ally – Web Accessibility & Usability <= 4.0.3 Unauthenticated SQL Injection via URL Path PoC, Patch Analysis & Rule
High CVE-2026-2413 in Pojo Accessibility (CVSS 7.5): Ally – Web Accessibility & Usability. Atomic Edge summarizes impact, exploitability, and patch details. Update to 4.1.0.
March 18, 2026
CVE-2026-1781: MC4WP: Mailchimp for WordPress <= 4.11.1 Missing Authorization to Unauthenticated Arbitrary Subscription Deletion PoC, Patch Analysis & Rule
Medium CVE-2026-1781 in Mailchimp For Wp (CVSS 6.5): MC4WP: Mailchimp for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.12.0.
March 18, 2026
CVE-2026-3453: ProfilePress <= 4.16.11 Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration PoC, Patch Analysis & Rule
High CVE-2026-3453 in Wp User Avatar (CVSS 8.1): ProfilePress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.16.12.
March 18, 2026
CVE-2025-13067: Royal Addons for Elementor <= 1.7.1049 Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass PoC, Patch Analysis & Rule
High CVE-2025-13067 in Royal Elementor Addons (CVSS 8.8): Royal Addons for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.7.1050.
March 18, 2026
CVE-2026-2707: weForms <= 1.6.27 Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API PoC, Patch Analysis & Rule
Medium CVE-2026-2707 in Weforms (CVSS 6.4): weForms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.6.28.
March 18, 2026
CVE-2026-2324: LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-2324 in Latepoint (CVSS 6.1): LatePoint – Calendar Booking Plugin for Appointments and Events. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.2.8.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
