Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-1656: Business Directory Plugin <= 6.4.20 Missing Authorization to Unauthenticated Arbitrary Listing Modification PoC, Patch Analysis & Rule

CVE-2026-1656 affects the Business Directory Plugin for WordPress (up to v6.4.20) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized listing modifications. Upgrade to v6.4.21 to mitigate this risk.
March 18, 2026

CVE-2026-1941: WP Event Aggregator <= 1.8.7 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2026-1941 affects the WP Event Aggregator plugin (up to v1.8.7) with a CVSS score of 6.4. Authenticated users can exploit stored XSS vulnerabilities. Update to v1.9.0 to mitigate risks.
March 18, 2026

CVE-2026-1860: Kali Forms <= 2.4.8 Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure PoC, Patch Analysis & Rule

CVE-2026-1860 affects the Kali Forms plugin for WordPress (up to version 2.4.8) with a CVSS score of 4.3. Authenticated users can exploit this medium-severity vulnerability to access sensitive data. Upgrade to version 2.4.9 to mitigate...
March 18, 2026

CVE-2026-1938: YayMail <= 4.3.2 Missing Authorization to Authenticated (Shop Manager+) License Key Deletion via '/yaymail-license/v1/license/delete' Endpoint PoC, Patch Analysis & Rule

CVE-2026-1938 affects YayMail plugin versions up to 4.3.2, allowing authenticated attackers to delete license keys due to a missing authorization check. Update to version 4.3.3 to mitigate this medium severity risk.
March 18, 2026

CVE-2026-1831: YayMail <= 4.3.2 Missing Authorization to Authenticated (Shop Manager+) Plugin Installation and Activation PoC, Patch Analysis & Rule

CVE-2026-1831 affects the YayMail plugin for WordPress (up to 4.3.2) with a CVSS score of 2.7. Authenticated attackers can exploit this low-severity flaw to install the YaySMTP plugin. Update to version 4.3.3 to mitigate risks.
March 18, 2026

CVE-2026-1937: YayMail <= 4.3.2 Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update via 'yaymail_import_state' AJAX Action PoC, Patch Analysis & Rule

CVE-2026-1937 affects YayMail plugin versions up to 4.3.2 with a critical CVSS score of 9.8. Authenticated attackers can exploit this flaw for privilege escalation. Update to version 4.3.3 to mitigate risks.
March 18, 2026

CVE-2026-2296: Product Addons for Woocommerce – Product Options with Custom Fields <= 3.1.0 Authenticated (Shop Manager+) Code Injection via Conditional Logic 'operator' Parameter PoC, Patch Analysis & Rule

CVE-2026-2296 affects Woo Custom Product Addons plugin version 3.1.0, allowing remote code execution due to insufficient input validation. Upgrade to version 3.1.1 to mitigate this high-severity vulnerability.
March 18, 2026

CVE-2026-1807: InteractiveCalculator for WordPress <= 1.0.3 Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-1807 affects the InteractiveCalculator plugin (v1.0.3) with a medium severity CVSS score of 6.4. Authenticated users can exploit stored XSS vulnerabilities, emphasizing the need for immediate patching and input sanitization.
March 18, 2026

CVE-2026-2281: Private Comment <= 0.0.4 Authenticated (Administrator+) Stored Cross-Site Scripting via Label Text Setting PoC, Patch Analysis & Rule

CVE-2026-2281 affects the Private Comment plugin for WordPress (up to v0.0.4) with a medium severity CVSS score of 4.4. Admin-level users can exploit this XSS vulnerability, so upgrade to v0.0.5 to mitigate risks.
March 18, 2026

CVE-2026-1943: YayMail <= 4.3.2 Authenticated (Shop Manager+) Stored Cross-Site Scripting via Template Elements PoC, Patch Analysis & Rule

CVE-2026-1943 affects the YayMail plugin (up to v4.3.2) with a medium severity (CVSS 4.4) stored XSS vulnerability. Users should upgrade to v4.3.3 to mitigate risks associated with this flaw.
March 18, 2026

CVE-2026-2019: Cart All In One For WooCommerce <= 1.1.21 Authenticated (Administrator+) Code Injection via 'sc_assign_page' Setting PoC, Patch Analysis & Rule

CVE-2026-2019 affects the Woo Cart All In One plugin (v1.1.21 and below) with a CVSS score of 7.2. It allows authenticated attackers to execute arbitrary PHP code. Users should update to the patched version to mitigate this risk.
March 18, 2026

CVE-2026-2633: Gutenberg Blocks with AI by Kadence WP <= 3.6.1 Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload PoC, Patch Analysis & Rule

CVE-2026-2633 affects Kadence Blocks plugin versions up to 3.6.1, allowing authenticated users to upload arbitrary images. Update to 3.6.2 to mitigate this medium severity vulnerability.
March 18, 2026

CVE-2026-1857: Gutenberg Blocks with AI by Kadence WP <= 3.6.1 Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter PoC, Patch Analysis & Rule

CVE-2026-1857 affects Kadence Blocks plugin versions up to 3.6.1, with a CVSS score of 4.3. Authenticated users can exploit this medium-severity SSRF vulnerability. Update to version 3.6.2 to mitigate risks.
March 18, 2026

CVE-2026-1666: Download Manager <= 3.3.46 Reflected Cross-Site Scripting via 'redirect_to' Parameter PoC, Patch Analysis & Rule

CVE-2026-1666 affects the Download Manager plugin (up to v3.3.46) with a medium severity CVSS score of 6.1 due to reflected XSS. Users should update to v3.3.47 to mitigate the risk of script injection.
March 18, 2026

CVE-2026-1640: Taskbuilder <= 5.0.2 Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation PoC, Patch Analysis & Rule

CVE-2026-1640 affects the Taskbuilder plugin (up to v5.0.2) with a medium severity (CVSS 4.3) authentication bypass. Update to v5.0.3 to mitigate risks from unauthorized comment submissions.
March 18, 2026

CVE-2026-1072: Keybase.io Verification <= 1.4.5 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

CVE-2026-1072 affects the Wp Keybase Verification plugin (up to v1.4.5) with a medium severity CVSS score of 4.3 due to a CSRF vulnerability. Update to v1.4.6 to mitigate unauthorized changes to settings.
March 18, 2026

CVE-2026-1906: PDF Invoices & Packing Slips for WooCommerce <= 5.6.0 Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification PoC, Patch Analysis & Rule

CVE-2026-1906 affects WooCommerce PDF Invoices & Packing Slips plugin versions up to 5.6.0. This medium severity vulnerability allows authenticated attackers to modify customer identifiers, impacting order routing. Upgrade to 5.7.0 to...
March 18, 2026

CVE-2026-2023: WP Plugin Info Card <= 6.2.0 Cross-Site Request Forgery to Arbitrary Custom Plugin Entry Creation PoC, Patch Analysis & Rule

CVE-2026-2023 affects the WP Plugin Info Card plugin (up to version 6.2.0) with a medium severity CVSS score of 4.3. Unauthenticated attackers can exploit this CSRF vulnerability; update to version 6.3.0 to mitigate.
March 18, 2026

CVE-2026-1639: Taskbuilder <= 5.0.2 Authenticated (Subscriber+) SQL Injection via 'order' and 'sort_by' Parameters PoC, Patch Analysis & Rule

CVE-2026-1639 affects the Taskbuilder plugin (up to v5.0.2) with a medium severity SQL injection vulnerability (CVSS 6.5). Users should upgrade to v5.0.3 to mitigate risks from authenticated attacks.
March 18, 2026

CVE-2025-11737: VK All in One Expansion Unit <= 9.112.3 Authenticated (Contributor+) Stored Cross-Site Scripting via SNS Title PoC, Patch Analysis & Rule

CVE-2025-11737 affects the VK All In One Expansion Unit plugin for WordPress (up to 9.112.3) with a CVSS score of 6.4. Authenticated attackers can exploit this medium severity XSS vulnerability, so ensure prompt patching.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works