Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2025-11725: Aruba HiSpeed Cache <= 3.0.2 Missing Authorization to Unauthenticated Plugin's Settings Modification PoC, Patch Analysis & Rule

CVE-2025-11725 affects the Aruba HiSpeed Cache plugin (up to version 3.0.2) with a CVSS score of 6.5. Unauthenticated attackers can modify settings and features, highlighting the need for immediate patching.
March 18, 2026

CVE-2025-12451: Easy SVG Support <= 4.0 Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload PoC, Patch Analysis & Rule

CVE-2025-12451 affects the Easy SVG Support plugin for WordPress (up to v4.0) with a medium severity CVSS score of 6.1. Patch to v4.1 to mitigate stored XSS vulnerabilities from SVG file uploads.
March 18, 2026

CVE-2025-12172: Mailchimp List Subscribe Form <= 2.0.0 Cross-Site Request Forgery to Mailchimp List Change PoC, Patch Analysis & Rule

CVE-2025-12172 affects the Mailchimp List Subscribe Form plugin (up to v2.0.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Update to v2.0.1 to mitigate the risk of unauthorized list changes by unauthenticated attackers.
March 18, 2026

CVE-2025-11706: Aruba HiSpeed Cache <= 3.0.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-11706 affects the Aruba HiSpeed Cache plugin (up to 3.0.2) with a medium severity CVSS score of 6.1. Unauthenticated attackers can exploit this reflected XSS vulnerability, so ensure you update to the patched version.
March 18, 2026

CVE-2025-11754: Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.1.2 Missing Authorization to Sensitive Information Exposure PoC, Patch Analysis & Rule

CVE-2025-11754 affects the GDPR Cookie Consent plugin (v4.1.2) with a CVSS score of 7.5. Unauthenticated attackers can access sensitive data. Update to v4.1.3 to mitigate this risk.
March 18, 2026

CVE-2025-12081: ACF Photo Gallery Field <= 3.0 Missing Authorization to Authenticated (Subscriber+) Attachment Metadata Modification PoC, Patch Analysis & Rule

CVE-2025-12081 affects the Navz Photo Gallery plugin (up to v3.0) with a medium severity (CVSS 4.3) vulnerability. Authenticated attackers can modify media metadata. Update to v3.1 to mitigate this risk.
March 18, 2026

CVE-2026-2386: The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type' PoC, Patch Analysis & Rule

CVE-2026-2386 affects The Plus Addons for Elementor plugin (up to v6.4.7) with a medium severity (CVSS 4.3). Authenticated attackers can exploit this to create unauthorized draft posts. Upgrade to v6.4.8 to mitigate.
March 18, 2026

CVE-2025-13732: s2Member <= 251005 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode PoC, Patch Analysis & Rule

CVE-2025-13732 affects the s2Member plugin for WordPress, with a CVSS score of 6.4. Users should update to version 260101 to mitigate the stored XSS vulnerability that allows authenticated attackers to inject scripts.
March 18, 2026

CVE-2026-1581: wpForo Forum <= 2.4.14 Unauthenticated Time-Based SQL Injection PoC, Patch Analysis & Rule

CVE-2026-1581 affects wpForo plugin versions up to 2.4.14 with a high severity CVSS score of 7.5. Users should upgrade to version 2.4.15 to mitigate the SQL injection risk that could expose sensitive database information.
March 18, 2026

CVE-2026-23541: Mail Mint <= 1.19.4 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-23541 affects the Mail Mint plugin for WordPress (up to v1.19.4) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Update to v1.19.5 to mitigate this risk.
March 18, 2026

CVE-2026-23549: WpEvently <= 5.1.1 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

CVE-2026-23549 affects the Mage Eventpress plugin (up to version 5.1.1) with a high severity score of 8.1 due to a PHP object injection vulnerability. Users should patch immediately to mitigate risks of unauthorized access.
March 18, 2026

CVE-2025-14864: Virusdie <= 1.1.7 Missing Authorization to Authenticated (Subscriber+) API Key Disclosure PoC, Patch Analysis & Rule

CVE-2025-14864 affects the Virusdie plugin (up to 1.1.7) with a CVSS score of 4.3, allowing authenticated users to expose sensitive API keys. Upgrade to version 1.1.8 to mitigate this vulnerability.
March 18, 2026

CVE-2025-14294: Razorpay for WooCommerce <= 4.7.8 Missing Authentication to Unauthenticated Order Modification PoC, Patch Analysis & Rule

CVE-2025-14294 affects Woo Razorpay plugin versions up to 4.7.8, allowing unauthenticated attackers to modify order contact info. Upgrade to 4.7.9 to mitigate this medium severity vulnerability (CVSS 5.3).
March 18, 2026

CVE-2026-25375: Image Photo Gallery Final Tiles Grid <= 3.6.10 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-25375 affects the Final Tiles Grid Gallery Lite plugin (up to version 3.6.10) with a medium severity (CVSS 4.3) vulnerability, allowing unauthorized gallery deletions. Upgrade to version 3.6.11 to mitigate this risk.
March 18, 2026

CVE-2025-12707: Library Management System <= 3.2.1 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2025-12707 affects the Library Management System plugin for WordPress (up to v3.2.1) with a CVSS score of 7.5. Unauthenticated SQL injection can expose sensitive data; update to v3.3 to mitigate this risk.
March 18, 2026

CVE-2025-13079: Popup Builder Create highly converting, mobile friendly marketing popups. <= 4.4.2 Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens PoC, Patch Analysis & Rule

CVE-2025-13079 affects the Popup Builder plugin (up to v4.4.2) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit predictable tokens to unsubscribe users. Update to v4.4.3 to mitigate this risk.
March 18, 2026

CVE-2026-1461: Simple Membership <= 4.7.0 Unauthenticated Improper Handling of Missing Values PoC, Patch Analysis & Rule

CVE-2026-1461 affects Simple Membership plugin versions up to 4.7.0, with a CVSS score of 6.5. Unauthenticated attackers can manipulate subscriptions via the Stripe webhook. Update to version 4.7.1 to mitigate this risk.
March 18, 2026

CVE-2026-1219: MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 4.0 5.10 Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure PoC, Patch Analysis & Rule

CVE-2026-1219 affects the Mp3 Music Player By Sonaar plugin (versions 4.0-5.10) with a medium severity (CVSS 5.3) IDOR vulnerability. Update to version 5.11 to prevent unauthorized access to private post content.
March 18, 2026

CVE-2025-15041: BackWPup 5.0.0 5.6.2 Authenticated (BackWPup Helper+) Privilege Escalation via Arbitrary Options Update PoC, Patch Analysis & Rule

CVE-2025-15041 affects the BackWPup plugin (versions 5.0.0 to 5.6.2) with a CVSS score of 7.2. This high-severity vulnerability allows authenticated attackers to escalate privileges. Update to version 5.6.3 to mitigate risks.
March 18, 2026

CVE-2025-12027: Mesmerize Companion <= 1.6.158 Missing Authorization Authenticated (Subscriber+) Settings Update PoC, Patch Analysis & Rule

CVE-2025-12027 affects the Mesmerize Companion plugin (up to v1.6.158) with a medium severity (CVSS 4.3) flaw allowing authenticated users to modify page settings. Ensure you update to the patched version to mitigate this risk.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works