
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1656: Business Directory Plugin <= 6.4.20 Missing Authorization to Unauthenticated Arbitrary Listing Modification PoC, Patch Analysis & Rule
CVE-2026-1656 affects the Business Directory Plugin for WordPress (up to v6.4.20) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized listing modifications. Upgrade to v6.4.21 to mitigate this risk.
March 18, 2026
CVE-2026-1941: WP Event Aggregator <= 1.8.7 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
CVE-2026-1941 affects the WP Event Aggregator plugin (up to v1.8.7) with a CVSS score of 6.4. Authenticated users can exploit stored XSS vulnerabilities. Update to v1.9.0 to mitigate risks.
March 18, 2026
CVE-2026-1860: Kali Forms <= 2.4.8 Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure PoC, Patch Analysis & Rule
CVE-2026-1860 affects the Kali Forms plugin for WordPress (up to version 2.4.8) with a CVSS score of 4.3. Authenticated users can exploit this medium-severity vulnerability to access sensitive data. Upgrade to version 2.4.9 to mitigate...
March 18, 2026
CVE-2026-1938: YayMail <= 4.3.2 Missing Authorization to Authenticated (Shop Manager+) License Key Deletion via '/yaymail-license/v1/license/delete' Endpoint PoC, Patch Analysis & Rule
CVE-2026-1938 affects YayMail plugin versions up to 4.3.2, allowing authenticated attackers to delete license keys due to a missing authorization check. Update to version 4.3.3 to mitigate this medium severity risk.
March 18, 2026
CVE-2026-1831: YayMail <= 4.3.2 Missing Authorization to Authenticated (Shop Manager+) Plugin Installation and Activation PoC, Patch Analysis & Rule
CVE-2026-1831 affects the YayMail plugin for WordPress (up to 4.3.2) with a CVSS score of 2.7. Authenticated attackers can exploit this low-severity flaw to install the YaySMTP plugin. Update to version 4.3.3 to mitigate risks.
March 18, 2026
CVE-2026-1937: YayMail <= 4.3.2 Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update via 'yaymail_import_state' AJAX Action PoC, Patch Analysis & Rule
CVE-2026-1937 affects YayMail plugin versions up to 4.3.2 with a critical CVSS score of 9.8. Authenticated attackers can exploit this flaw for privilege escalation. Update to version 4.3.3 to mitigate risks.
March 18, 2026
CVE-2026-2296: Product Addons for Woocommerce – Product Options with Custom Fields <= 3.1.0 Authenticated (Shop Manager+) Code Injection via Conditional Logic 'operator' Parameter PoC, Patch Analysis & Rule
CVE-2026-2296 affects Woo Custom Product Addons plugin version 3.1.0, allowing remote code execution due to insufficient input validation. Upgrade to version 3.1.1 to mitigate this high-severity vulnerability.
March 18, 2026
CVE-2026-1807: InteractiveCalculator for WordPress <= 1.0.3 Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1807 affects the InteractiveCalculator plugin (v1.0.3) with a medium severity CVSS score of 6.4. Authenticated users can exploit stored XSS vulnerabilities, emphasizing the need for immediate patching and input sanitization.
March 18, 2026
CVE-2026-2281: Private Comment <= 0.0.4 Authenticated (Administrator+) Stored Cross-Site Scripting via Label Text Setting PoC, Patch Analysis & Rule
CVE-2026-2281 affects the Private Comment plugin for WordPress (up to v0.0.4) with a medium severity CVSS score of 4.4. Admin-level users can exploit this XSS vulnerability, so upgrade to v0.0.5 to mitigate risks.
March 18, 2026
CVE-2026-1943: YayMail <= 4.3.2 Authenticated (Shop Manager+) Stored Cross-Site Scripting via Template Elements PoC, Patch Analysis & Rule
CVE-2026-1943 affects the YayMail plugin (up to v4.3.2) with a medium severity (CVSS 4.4) stored XSS vulnerability. Users should upgrade to v4.3.3 to mitigate risks associated with this flaw.
March 18, 2026
CVE-2026-2019: Cart All In One For WooCommerce <= 1.1.21 Authenticated (Administrator+) Code Injection via 'sc_assign_page' Setting PoC, Patch Analysis & Rule
CVE-2026-2019 affects the Woo Cart All In One plugin (v1.1.21 and below) with a CVSS score of 7.2. It allows authenticated attackers to execute arbitrary PHP code. Users should update to the patched version to mitigate this risk.
March 18, 2026
CVE-2026-2633: Gutenberg Blocks with AI by Kadence WP <= 3.6.1 Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload PoC, Patch Analysis & Rule
CVE-2026-2633 affects Kadence Blocks plugin versions up to 3.6.1, allowing authenticated users to upload arbitrary images. Update to 3.6.2 to mitigate this medium severity vulnerability.
March 18, 2026
CVE-2026-1857: Gutenberg Blocks with AI by Kadence WP <= 3.6.1 Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter PoC, Patch Analysis & Rule
CVE-2026-1857 affects Kadence Blocks plugin versions up to 3.6.1, with a CVSS score of 4.3. Authenticated users can exploit this medium-severity SSRF vulnerability. Update to version 3.6.2 to mitigate risks.
March 18, 2026
CVE-2026-1666: Download Manager <= 3.3.46 Reflected Cross-Site Scripting via 'redirect_to' Parameter PoC, Patch Analysis & Rule
CVE-2026-1666 affects the Download Manager plugin (up to v3.3.46) with a medium severity CVSS score of 6.1 due to reflected XSS. Users should update to v3.3.47 to mitigate the risk of script injection.
March 18, 2026
CVE-2026-1640: Taskbuilder <= 5.0.2 Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation PoC, Patch Analysis & Rule
CVE-2026-1640 affects the Taskbuilder plugin (up to v5.0.2) with a medium severity (CVSS 4.3) authentication bypass. Update to v5.0.3 to mitigate risks from unauthorized comment submissions.
March 18, 2026
CVE-2026-1072: Keybase.io Verification <= 1.4.5 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule
CVE-2026-1072 affects the Wp Keybase Verification plugin (up to v1.4.5) with a medium severity CVSS score of 4.3 due to a CSRF vulnerability. Update to v1.4.6 to mitigate unauthorized changes to settings.
March 18, 2026
CVE-2026-1906: PDF Invoices & Packing Slips for WooCommerce <= 5.6.0 Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification PoC, Patch Analysis & Rule
CVE-2026-1906 affects WooCommerce PDF Invoices & Packing Slips plugin versions up to 5.6.0. This medium severity vulnerability allows authenticated attackers to modify customer identifiers, impacting order routing. Upgrade to 5.7.0 to...
March 18, 2026
CVE-2026-2023: WP Plugin Info Card <= 6.2.0 Cross-Site Request Forgery to Arbitrary Custom Plugin Entry Creation PoC, Patch Analysis & Rule
CVE-2026-2023 affects the WP Plugin Info Card plugin (up to version 6.2.0) with a medium severity CVSS score of 4.3. Unauthenticated attackers can exploit this CSRF vulnerability; update to version 6.3.0 to mitigate.
March 18, 2026
CVE-2026-1639: Taskbuilder <= 5.0.2 Authenticated (Subscriber+) SQL Injection via 'order' and 'sort_by' Parameters PoC, Patch Analysis & Rule
CVE-2026-1639 affects the Taskbuilder plugin (up to v5.0.2) with a medium severity SQL injection vulnerability (CVSS 6.5). Users should upgrade to v5.0.3 to mitigate risks from authenticated attacks.
March 18, 2026
CVE-2025-11737: VK All in One Expansion Unit <= 9.112.3 Authenticated (Contributor+) Stored Cross-Site Scripting via SNS Title PoC, Patch Analysis & Rule
CVE-2025-11737 affects the VK All In One Expansion Unit plugin for WordPress (up to 9.112.3) with a CVSS score of 6.4. Authenticated attackers can exploit this medium severity XSS vulnerability, so ensure prompt patching.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
