
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-2232: Product Table and List Builder for WooCommerce Lite <= 4.6.2 Unauthenticated Time-Based SQL Injection via 'search' Parameter PoC, Patch Analysis & Rule
CVE-2026-2232 affects the Wc Product Table Lite plugin (up to v4.6.2) with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows data extraction; users should upgrade to v4.6.3 to mitigate risks.
March 18, 2026
CVE-2025-12845: Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent 0.5.4 1.2.1 Missing Authorization to Authenticated (Subscriber+) Information Exposure and Privilege Escalation PoC, Patch Analysis & Rule
CVE-2025-12845 affects the Tablesome plugin (versions 0.5.4 to 1.2.1) with a CVSS score of 8.8. It allows authenticated users to access sensitive data, leading to privilege escalation. Update to version 1.2.2 to mitigate this risk.
March 18, 2026
CVE-2025-13612: Album and Image Gallery Plus Lightbox <= 2.1.7 Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin's Shortcode PoC, Patch Analysis & Rule
CVE-2025-13612 affects the Album And Image Gallery Plus Lightbox plugin (up to 2.1.7) with a medium severity (CVSS 6.4) stored XSS vulnerability. Update to 2.1.8 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026
CVE-2026-23545: Aruba HiSpeed Cache <= 3.0.4 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-23545 affects the Aruba HiSpeed Cache plugin for WordPress (up to 3.0.4) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Update to version 3.0.5 to mitigate this risk.
March 18, 2026
CVE-2025-12448: Smartsupp – live chat, AI shopping assistant and chatbots <= 3.9.1 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-12448 affects Smartsupp Live Chat plugin versions up to 3.9.1, allowing authenticated users to exploit stored XSS. Upgrade to 3.9.2 to mitigate this medium severity vulnerability.
March 18, 2026
CVE-2025-13738: Easy Table of Contents <= 2.0.78 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-13738 affects the Easy Table Of Contents plugin (up to 2.0.78) with a medium severity (CVSS 6.4) XSS vulnerability. Users should update to version 2.0.79 to mitigate the risk of script injection by authenticated attackers.
March 18, 2026
CVE-2025-13113: Web Accessibility by accessiBe <= 2.11 Unauthenticated Sensitive Information Exposure PoC, Patch Analysis & Rule
CVE-2025-13113 affects the Accessibe WordPress plugin (up to v2.11) with a medium severity (CVSS 5.3) vulnerability. Unauthenticated users can access sensitive data via the browser console. Upgrade to v2.12 to mitigate this risk.
March 18, 2026
CVE-2025-13842: Breadcrumb NavXT <= 7.5.0 Missing Authorization to Sensitive Information Exposure PoC, Patch Analysis & Rule
CVE-2025-13842 affects the Breadcrumb NavXT plugin (up to version 7.5.0), allowing unauthorized access to draft and private post data. Update to version 7.5.1 to mitigate this medium severity vulnerability.
March 18, 2026
CVE-2025-14445: Image Hotspot by DevVN <= 1.2.9 Authenticated (Author+) Stored Cross-Site Scripting via Custom Field Meta PoC, Patch Analysis & Rule
CVE-2025-14445 affects the Devvn Image Hotspot plugin (up to v1.2.9) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should upgrade to v1.3.0 to mitigate risks from authenticated attackers.
March 18, 2026
CVE-2026-2426: WP-DownloadManager <= 1.69 Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'file' Parameter PoC, Patch Analysis & Rule
CVE-2026-2426 affects WP-DownloadManager plugin (up to v1.69) with a CVSS score of 6.5. This medium-severity path traversal vulnerability allows authenticated attackers to delete arbitrary files. Update to v1.69.1 to mitigate risks.
March 18, 2026
CVE-2026-0549: Groups <= 3.10.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'groups_group_info' Shortcode PoC, Patch Analysis & Rule
CVE-2026-0549 affects the Groups plugin for WordPress (up to version 3.10.0) with a medium severity CVSS score of 6.4. Authenticated users can exploit this stored XSS vulnerability, so update to version 3.11.0 to mitigate risks.
March 18, 2026
CVE-2025-14444: RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.9 Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment PoC, Patch Analysis & Rule
CVE-2025-14444 affects the Custom Registration Form Builder With Submission Manager plugin (v6.0.6.9) with a medium severity (CVSS 5.3). Patch to v6.0.7.0 to prevent unauthenticated payment bypass and ensure proper payment verification.
March 18, 2026
CVE-2025-14983: Advanced Custom Fields: Font Awesome <= 5.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-14983 affects the Advanced Custom Fields Font Awesome plugin (up to 5.0.1) with a medium severity (CVSS 6.4) XSS vulnerability. Update to version 5.0.2 to mitigate risks from authenticated attackers.
March 18, 2026
CVE-2025-13048: Official StatCounter Plugin <= 2.1.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Nickname PoC, Patch Analysis & Rule
CVE-2025-13048 affects the Official StatCounter Plugin for WordPress (up to 2.1.0) with a medium severity CVSS of 6.4. Users should upgrade to version 2.1.1 to mitigate the stored XSS vulnerability.
March 18, 2026
CVE-2026-1942: Blog2Social: Social Media Auto Post & Scheduler <= 8.7.4 Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification PoC, Patch Analysis & Rule
CVE-2026-1942 affects the Blog2Social plugin (up to v8.7.4) with a CVSS score of 6.5. It allows authenticated users to modify post content. Upgrade to v8.7.5 to mitigate this vulnerability.
March 18, 2026
CVE-2025-11185: Complianz | GDPR/CCPA Cookie Consent <= 7.4.3 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode PoC, Patch Analysis & Rule
CVE-2025-11185 affects the Complianz GDPR/CCPA plugin (up to v7.4.3) with a CVSS score of 6.4. Authenticated attackers can exploit stored XSS vulnerabilities. Upgrade to v7.4.4 to mitigate risks.
March 18, 2026
CVE-2026-2126: User Submitted Posts <= 20260113 Incorrect Authorization to Unauthenticated Category Restriction Bypass via 'user-submitted-category' Parameter PoC, Patch Analysis & Rule
CVE-2026-2126 affects the User Submitted Posts plugin (up to 20260113) with a CVSS score of 5.3. Unauthenticated attackers can bypass category restrictions. Update to version 20260217 to mitigate this risk.
March 18, 2026
CVE-2026-2495: WPNakama <= 0.6.5 Unauthenticated SQL Injection via 'order' REST API Parameter PoC, Patch Analysis & Rule
CVE-2026-2495 reveals a high severity SQL injection vulnerability in the WPNakama plugin for WordPress, affecting versions up to 0.6.5. Patching is crucial to prevent unauthorized database access.
March 18, 2026
CVE-2025-13727: Video Share VOD <= 2.7.11 Authenticated (Editor+) Stored Cross-Site Scripting via Custom Field Meta Values PoC, Patch Analysis & Rule
CVE-2025-13727 affects the Video Share VOD plugin (up to 2.7.11) with a medium severity CVSS score of 4.4, allowing authenticated users to exploit stored XSS. Patching is essential to mitigate risks in multisite environments.
March 18, 2026
CVE-2026-2127: SiteOrigin Widgets Bundle <= 1.70.4 Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution PoC, Patch Analysis & Rule
CVE-2026-2127 affects the SiteOrigin Widgets Bundle plugin (up to v1.70.4) with a medium severity (CVSS 5.4) remote code execution vulnerability. Patch to v1.71.0 to mitigate unauthorized shortcode execution risks.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
