Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-2371: Greenshift <= 12.8.3 Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load' PoC, Patch Analysis & Rule

Medium CVE-2026-2371 in Greenshift Animation And Page Builder Blocks (CVSS 5.3): Greenshift. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 12.8.4.
March 18, 2026

CVE-2026-2589: Greenshift – animation and page builder blocks <= 12.8.3 Unauthenticated Sensitive Information Exposure via Settings Backup PoC, Patch Analysis & Rule

Medium CVE-2026-2589 in Greenshift Animation And Page Builder Blocks (CVSS 5.3): Greenshift – animation and page builder blocks. Atomic Edge summarizes impact, exploitability, and patch details. Update to 12.8.4.
March 18, 2026

CVE-2026-1981: Winston AI <= 0.0.3 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion PoC, Patch Analysis & Rule

Medium CVE-2026-1981 in Winston Ai Wp (CVSS 4.3): Winston AI. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 0.0.4.
March 18, 2026

CVE-2026-2593: Greenshift – animation and page builder blocks <= 12.8.5 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2026-2593 in Greenshift Animation And Page Builder Blocks (CVSS 6.4): Greenshift – animation and page builder blocks. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 12.8.6.
March 18, 2026

CVE-2026-3459: Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule

High CVE-2026-3459 in Drag And Drop Multiple File Upload Contact Form 7 (CVSS 8.1): Drag and Drop Multiple File Upload for Contact Form 7. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update...
March 18, 2026

CVE-2026-2830: WP All Import <= 4.0.0 Reflected Cross-Site Scripting via 'filepath' PoC, Patch Analysis & Rule

Medium CVE-2026-2830 in Wp All Import (CVSS 6.1): WP All Import. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.0.1.
March 18, 2026

CVE-2026-27095: Bus Ticket Booking with Seat Reservation <= 5.6.2 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

High CVE-2026-27095 in Bus Ticket Booking With Seat Reservation (CVSS 8.1): Bus Ticket Booking with Seat Reservation. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-22485: My Album Gallery <= 1.0.4 Authenticated (Subscriber+) Arbitrary File Deletion PoC, Patch Analysis & Rule

High CVE-2026-22485 in My Album Gallery (CVSS 8.1): My Album Gallery. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-22480: WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More <= 2.3.3 Authenticated (Shop manager+) PHP Object Injection PoC, Patch Analysis & Rule

Medium CVE-2026-22480 in Webtoffee Product Feed (CVSS 6.6): WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
March 18, 2026

CVE-2026-22491: My auctions allegro <= 3.6.34 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2026-22491 in My Auctions Allegro Free Edition (CVSS 6.1): My auctions allegro. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-3072: Media Library Assistant <= 3.33 Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification PoC, Patch Analysis & Rule

Medium CVE-2026-3072 in Media Library Assistant (CVSS 4.3): Media Library Assistant. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.34.
March 18, 2026

CVE-2025-69347: Subscription for WooCommerce – WordPress Recurring Payments Plugin <= 1.8.10 Authenticated (Customer+) Insecure Direct Object Reference PoC, Patch Analysis & Rule

Medium CVE-2025-69347 in Subscription (CVSS 4.3): Subscription for WooCommerce – WordPress Recurring Payments Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-2893: Page and Post Clone <= 6.3 Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-2893 in Page Or Post Clone (CVSS 6.5): Page and Post Clone. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-22484: Lisfinity Core Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.5.0 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-22484 in Lisfinity Core (CVSS 7.5): Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-2365: Fluent Forms Pro <= 6.1.17 Unauthenticated Stored Cross-Site Scripting via Draft Form Submission PoC, Patch Analysis & Rule

High CVE-2026-2365 in Fluentformpro (CVSS 7.2): Fluent Forms Pro. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-2899: Fluent Forms Pro Add On Pack <= 6.1.17 Missing Authorization to Unauthenticated Arbitrary Attachment Deletion PoC, Patch Analysis & Rule

Medium CVE-2026-2899 in Fluentformpro (CVSS 6.5): Fluent Forms Pro Add On Pack. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026

CVE-2026-3034: OoohBoi Steroids for Elementor <= 2.1.24 Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls PoC, Patch Analysis & Rule

Medium CVE-2026-3034 in Ooohboi Steroids For Elementor (CVSS 6.4): OoohBoi Steroids for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.25.
March 18, 2026

CVE-2025-68515: WP Booking System – Booking Calendar <= 2.0.19.12 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

Medium CVE-2025-68515 in Wp Booking System (CVSS 5.3): WP Booking System – Booking Calendar. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.0.19.13.
March 18, 2026

CVE-2026-2599: Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 Unauthenticated PHP Object Injection via 'download_csv' PoC, Patch Analysis & Rule

Critical CVE-2026-2599 in Contact Form Entries (CVSS 9.8): Database for Contact Form 7, WPforms, Elementor forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.4.8.
March 18, 2026

CVE-2026-3352: Easy PHP Settings <= 1.0.4 Authenticated (Administrator+) PHP Code Injection via 'wp_memory_limit' Setting PoC, Patch Analysis & Rule

High CVE-2026-3352 in Easy Php Settings (CVSS 7.2): Easy PHP Settings. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.0.5.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works