
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
June 27, 2026
CVE-2026-54836: YMC Filter <= 3.11.5 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-54836 affects the YMC Smart Filter plugin for WordPress (up to version 3.11.5) with a CVSS score of 7.5. Unauthenticated SQL injection could expose sensitive data; update to 3.11.6 to mitigate this risk.
June 27, 2026
CVE-2026-56009: Bricksable for Bricks Builder <= 1.6.83 Authenticated (Author+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-56009 affects the Bricksable plugin for WordPress (up to 1.6.83) with a medium severity (CVSS 6.4) stored XSS vulnerability. Update to version 1.6.84 to mitigate risks from authenticated attackers injecting scripts.
June 26, 2026
CVE-2026-12432: Stripe Payment Forms by WP Full Pay <= 8.4.3 Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter PoC, Patch Analysis & Rule
CVE-2026-12432 affects WP Full Stripe Free plugin versions up to 8.4.3, with a medium severity score of 5.3. Unauthenticated attackers can manipulate payment records; update to version 8.5.0 to mitigate this risk.
June 26, 2026
CVE-2026-11364: Product Specifications for Woocommerce <= 0.8.9 Missing Authorization to Authenticated (Subscriber+) Arbitrary Attribute/Group Creation, Modification, and Deletion via 'dwps_modify_groups' and 'dwps_modify_attributes' AJAX Actions PoC, Patch Analysis & Rule
CVE-2026-11364 affects the Product Specifications plugin for WooCommerce (up to v0.8.9) with a CVSS score of 4.3. Patch to v0.8.10 to prevent unauthorized data modification by authenticated users.
June 26, 2026
CVE-2026-9233: Quiz and Survey Master (QSM) <= 11.1.4 Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action PoC, Patch Analysis & Rule
CVE-2026-9233 affects the Quiz Master Next plugin (up to version 11.1.4) with a medium severity (CVSS 4.3) authentication bypass. Update to version 11.1.5 to mitigate risks of unauthorized access and potential data manipulation.
June 26, 2026
CVE-2026-9242: RegistrationMagic <= 6.0.8.6 Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN Request PoC, Patch Analysis & Rule
CVE-2026-9242 affects the Custom Registration Form Builder plugin (up to version 6.0.8.6) with a CVSS score of 5.3. Unauthenticated attackers can bypass authentication. Update to version 6.0.8.7 to mitigate this risk.
June 26, 2026
CVE-2026-11597: Surbma | Infusionsoft Shortcode <= 2.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
CVE-2026-11597 affects the Surbma Infusionsoft Shortcode plugin (up to 2.0.1) with a CVSS score of 6.4. Authenticated users can exploit this XSS vulnerability; update to version 2.0.2 to mitigate risks.
June 26, 2026
CVE-2026-11773: Masteriyo LMS <= 2.2.1 Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification PoC, Patch Analysis & Rule
CVE-2026-11773 affects the Masteriyo LMS plugin (up to v2.2.1) with a medium severity CVSS score of 4.3. Authenticated users can bypass authorization to modify course announcements. Upgrade to v2.3.0 to mitigate this risk.
June 26, 2026
CVE-2026-11987: Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter PoC, Patch Analysis & Rule
CVE-2026-11987 affects Dokan Lite plugin versions up to 5.0.4, allowing authenticated users to access other vendors' unpublished products. Upgrade to 5.0.5 to mitigate this medium severity remote code execution risk.
June 26, 2026
CVE-2026-11783: Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU PoC, Patch Analysis & Rule
CVE-2026-11783 affects Dokan Lite plugin versions up to 5.0.4, allowing stored XSS due to insufficient input sanitization. Update to 5.0.5 to mitigate risks from authenticated attackers injecting scripts into user sessions.
June 26, 2026
CVE-2026-12399: Gutenverse <= 3.8.0 Authenticated (Editor+) Stored Cross-Site Scripting via 'fonts[].font.font.value' Parameter PoC, Patch Analysis & Rule
CVE-2026-12399 affects Gutenverse plugin versions 3.8.0 and below, with a CVSS score of 4.4. Authenticated users can exploit this cross-site scripting vulnerability. Update to version 3.8.1 to mitigate risks.
June 26, 2026
CVE-2026-13295: Page Builder by SiteOrigin <= 2.34.3 Authenticated (Contributor+) Stored Cross-Site Scripting via panels_data Parameter PoC, Patch Analysis & Rule
CVE-2026-13295 affects the Siteorigin Panels plugin (up to v2.34.3) with a medium severity (CVSS 6.4) Stored XSS vulnerability. Users should update to v2.34.4 to mitigate risks from potential script injections.
June 26, 2026
CVE-2026-12415: Invoice Generator <= 1.0.0 Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter PoC, Patch Analysis & Rule
CVE-2026-12415 reveals a critical vulnerability in the Invoice Creator plugin for WordPress (CVSS 9.8). Unauthenticated attackers can escalate privileges and take over accounts. Update to the latest version to mitigate this risk.
June 26, 2026
CVE-2026-12404: NEX-Forms <= 9.2.2 Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class PoC, Patch Analysis & Rule
CVE-2026-12404 affects Nex Forms Express WP Form Builder versions up to 9.2.2, allowing unauthenticated users to access sensitive data. Upgrade to version 9.2.3 to mitigate this medium severity vulnerability.
June 26, 2026
CVE-2026-13333: Groundhogg <= 4.5.5 Authenticated (Sales Rep+) SQL Injection via 'query[select]' Parameter PoC, Patch Analysis & Rule
CVE-2026-13333 affects the Groundhogg plugin for WordPress (up to version 4.5.5) with a medium severity CVSS score of 6.5. Authenticated attackers can exploit this SQL injection vulnerability, so update to version 4.5.6 to mitigate risks.
June 26, 2026
CVE-2026-13335: CodePeople Post Map for Google Maps <= 1.2.6 Authenticated (Contributor +) Stored Cross-Site Scripting via 'cpm_point' Post Meta PoC, Patch Analysis & Rule
CVE-2026-13335 affects the CodePeople Post Map plugin (up to version 1.2.6) with a CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability, so update to version 1.2.7 to mitigate risks.
June 26, 2026
CVE-2026-13422: HD Quiz 2.2.0 2.2.1 Cross-Site Request Forgery via Multiple AJAX Handlers PoC, Patch Analysis & Rule
CVE-2026-13422 affects the HD Quiz plugin for WordPress (versions 2.2.0 to 2.2.1) with a CVSS score of 4.3. Patch to version 2.2.2 to mitigate Cross-Site Request Forgery risks that allow unauthorized changes to quizzes.
June 26, 2026
CVE-2026-13245: MaxButtons <= 9.8.5 Reflected Cross-Site Scripting via 'view' Parameter PoC, Patch Analysis & Rule
CVE-2026-13245 affects the MaxButtons plugin for WordPress (up to version 9.8.5) with a medium severity CVSS score of 6.1. Users should upgrade to version 9.8.6 to mitigate the reflected XSS vulnerability.
June 26, 2026
CVE-2026-13331: Groundhogg <= 4.5.5 Authenticated (Marketer+) SQL Injection via 'search' Parameter PoC, Patch Analysis & Rule
CVE-2026-13331 affects the Groundhogg plugin (up to v4.5.5) with a medium severity CVSS score of 6.5. Authenticated attackers can exploit SQL injection via the 'search' parameter. Upgrade to v4.5.6 to mitigate this risk.
June 26, 2026
CVE-2026-54835: Five Star Restaurant Menu and Food Ordering <= 2.5.2 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-54835 affects the Food And Drink Menu plugin for WordPress (up to version 2.5.2) with a medium severity score of 5.3. Update to version 2.5.3 to mitigate unauthorized access risks.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
