
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-2371: Greenshift <= 12.8.3 Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load' PoC, Patch Analysis & Rule
Medium CVE-2026-2371 in Greenshift Animation And Page Builder Blocks (CVSS 5.3): Greenshift. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 12.8.4.
March 18, 2026
CVE-2026-2589: Greenshift – animation and page builder blocks <= 12.8.3 Unauthenticated Sensitive Information Exposure via Settings Backup PoC, Patch Analysis & Rule
Medium CVE-2026-2589 in Greenshift Animation And Page Builder Blocks (CVSS 5.3): Greenshift – animation and page builder blocks. Atomic Edge summarizes impact, exploitability, and patch details. Update to 12.8.4.
March 18, 2026
CVE-2026-1981: Winston AI <= 0.0.3 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion PoC, Patch Analysis & Rule
Medium CVE-2026-1981 in Winston Ai Wp (CVSS 4.3): Winston AI. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 0.0.4.
March 18, 2026
CVE-2026-2593: Greenshift – animation and page builder blocks <= 12.8.5 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-2593 in Greenshift Animation And Page Builder Blocks (CVSS 6.4): Greenshift – animation and page builder blocks. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 12.8.6.
March 18, 2026
CVE-2026-3459: Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule
High CVE-2026-3459 in Drag And Drop Multiple File Upload Contact Form 7 (CVSS 8.1): Drag and Drop Multiple File Upload for Contact Form 7. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update...
March 18, 2026
CVE-2026-2830: WP All Import <= 4.0.0 Reflected Cross-Site Scripting via 'filepath' PoC, Patch Analysis & Rule
Medium CVE-2026-2830 in Wp All Import (CVSS 6.1): WP All Import. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.0.1.
March 18, 2026
CVE-2026-27095: Bus Ticket Booking with Seat Reservation <= 5.6.2 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-27095 in Bus Ticket Booking With Seat Reservation (CVSS 8.1): Bus Ticket Booking with Seat Reservation. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-22485: My Album Gallery <= 1.0.4 Authenticated (Subscriber+) Arbitrary File Deletion PoC, Patch Analysis & Rule
High CVE-2026-22485 in My Album Gallery (CVSS 8.1): My Album Gallery. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-22480: WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More <= 2.3.3 Authenticated (Shop manager+) PHP Object Injection PoC, Patch Analysis & Rule
Medium CVE-2026-22480 in Webtoffee Product Feed (CVSS 6.6): WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
March 18, 2026
CVE-2026-22491: My auctions allegro <= 3.6.34 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-22491 in My Auctions Allegro Free Edition (CVSS 6.1): My auctions allegro. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-3072: Media Library Assistant <= 3.33 Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification PoC, Patch Analysis & Rule
Medium CVE-2026-3072 in Media Library Assistant (CVSS 4.3): Media Library Assistant. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.34.
March 18, 2026
CVE-2025-69347: Subscription for WooCommerce – WordPress Recurring Payments Plugin <= 1.8.10 Authenticated (Customer+) Insecure Direct Object Reference PoC, Patch Analysis & Rule
Medium CVE-2025-69347 in Subscription (CVSS 4.3): Subscription for WooCommerce – WordPress Recurring Payments Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-2893: Page and Post Clone <= 6.3 Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-2893 in Page Or Post Clone (CVSS 6.5): Page and Post Clone. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-22484: Lisfinity Core Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.5.0 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
High CVE-2026-22484 in Lisfinity Core (CVSS 7.5): Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-2365: Fluent Forms Pro <= 6.1.17 Unauthenticated Stored Cross-Site Scripting via Draft Form Submission PoC, Patch Analysis & Rule
High CVE-2026-2365 in Fluentformpro (CVSS 7.2): Fluent Forms Pro. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-2899: Fluent Forms Pro Add On Pack <= 6.1.17 Missing Authorization to Unauthenticated Arbitrary Attachment Deletion PoC, Patch Analysis & Rule
Medium CVE-2026-2899 in Fluentformpro (CVSS 6.5): Fluent Forms Pro Add On Pack. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-3034: OoohBoi Steroids for Elementor <= 2.1.24 Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls PoC, Patch Analysis & Rule
Medium CVE-2026-3034 in Ooohboi Steroids For Elementor (CVSS 6.4): OoohBoi Steroids for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.25.
March 18, 2026
CVE-2025-68515: WP Booking System – Booking Calendar <= 2.0.19.12 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2025-68515 in Wp Booking System (CVSS 5.3): WP Booking System – Booking Calendar. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.0.19.13.
March 18, 2026
CVE-2026-2599: Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 Unauthenticated PHP Object Injection via 'download_csv' PoC, Patch Analysis & Rule
Critical CVE-2026-2599 in Contact Form Entries (CVSS 9.8): Database for Contact Form 7, WPforms, Elementor forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.4.8.
March 18, 2026
CVE-2026-3352: Easy PHP Settings <= 1.0.4 Authenticated (Administrator+) PHP Code Injection via 'wp_memory_limit' Setting PoC, Patch Analysis & Rule
High CVE-2026-3352 in Easy Php Settings (CVSS 7.2): Easy PHP Settings. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.0.5.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
