
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1906: PDF Invoices & Packing Slips for WooCommerce <= 5.6.0 Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification PoC, Patch Analysis & Rule
CVE-2026-1906 affects WooCommerce PDF Invoices & Packing Slips plugin versions up to 5.6.0. This medium severity vulnerability allows authenticated attackers to modify customer identifiers, impacting order routing. Upgrade to 5.7.0 to...
March 18, 2026
CVE-2026-2023: WP Plugin Info Card <= 6.2.0 Cross-Site Request Forgery to Arbitrary Custom Plugin Entry Creation PoC, Patch Analysis & Rule
CVE-2026-2023 affects the WP Plugin Info Card plugin (up to version 6.2.0) with a medium severity CVSS score of 4.3. Unauthenticated attackers can exploit this CSRF vulnerability; update to version 6.3.0 to mitigate.
March 18, 2026
CVE-2026-1639: Taskbuilder <= 5.0.2 Authenticated (Subscriber+) SQL Injection via 'order' and 'sort_by' Parameters PoC, Patch Analysis & Rule
CVE-2026-1639 affects the Taskbuilder plugin (up to v5.0.2) with a medium severity SQL injection vulnerability (CVSS 6.5). Users should upgrade to v5.0.3 to mitigate risks from authenticated attacks.
March 18, 2026
CVE-2025-11737: VK All in One Expansion Unit <= 9.112.3 Authenticated (Contributor+) Stored Cross-Site Scripting via SNS Title PoC, Patch Analysis & Rule
CVE-2025-11737 affects the VK All In One Expansion Unit plugin for WordPress (up to 9.112.3) with a CVSS score of 6.4. Authenticated attackers can exploit this medium severity XSS vulnerability, so ensure prompt patching.
March 18, 2026
CVE-2025-12071: Frontend User Notes <= 2.1.0 Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Note Modification PoC, Patch Analysis & Rule
CVE-2025-12071 affects the Frontend User Notes plugin for WordPress (up to 2.1.0) with a CVSS score of 4.3. Authenticated users can modify others' notes. Upgrade to version 2.1.1 to mitigate this risk.
March 18, 2026
CVE-2025-12356: Tickera – WordPress Event Ticketing <= 3.5.6.4 Missing Authorization to Authenticated (Subscriber+) Event/Post Status Update PoC, Patch Analysis & Rule
CVE-2025-12356 affects the Tickera Event Ticketing System plugin (versions
March 18, 2026
CVE-2025-12122: Popup Box – Easily Create WordPress Popups <= 3.2.12 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-12122 affects the Popup Box plugin (up to v3.2.12) with a medium severity CVSS score of 6.4. Authenticated users can exploit this XSS vulnerability, so update to v3.2.13 to mitigate risks.
March 18, 2026
CVE-2026-1304: Membership Plugin – Restrict Content <= 3.2.18 Authenticated (Administrator+) Stored Cross-Site Scripting via Invoice Settings PoC, Patch Analysis & Rule
CVE-2026-1304 affects the Restrict Content plugin (up to v3.2.18) with a medium severity CVSS score of 4.4. Admins should upgrade to v3.2.19 to mitigate the stored XSS risk from insufficient input sanitization.
March 18, 2026
CVE-2025-12075: Order Splitter for WooCommerce <= 5.3.5 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure PoC, Patch Analysis & Rule
CVE-2025-12075 affects the Woo Order Splitter plugin (up to v5.3.5) with a medium severity (CVSS 4.3) vulnerability allowing authenticated users to access sensitive order data. Update to v5.3.6 to mitigate this risk.
March 18, 2026
CVE-2026-1925: EmailKit – Email Customizer for WooCommerce & WP <= 1.6.2 Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Title Modification PoC, Patch Analysis & Rule
CVE-2026-1925 affects the Emailkit plugin (up to v1.6.2) with a CVSS score of 4.3, allowing authenticated users to modify post titles. Upgrade to v1.6.3 to mitigate this remote code execution risk.
March 18, 2026
CVE-2025-12037: WP 404 Auto Redirect <= 1.0.5 Authenticated (Admin+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-12037 affects the WP 404 Auto Redirect to Similar Post plugin (up to v1.0.5) with a CVSS score of 4.4. Administrators should update to v1.0.6 to mitigate the stored XSS vulnerability.
March 18, 2026
CVE-2026-1296: Frontend Post Submission Manager Lite <= 1.2.7 Unauthenticated Open Redirect via 'requested_page' Parameter PoC, Patch Analysis & Rule
CVE-2026-1296 affects Frontend Post Submission Manager Lite versions up to 1.2.7 with a medium severity (CVSS 6.1) open redirection vulnerability. Upgrade to 1.2.8 to mitigate risks of user redirection to malicious sites.
March 18, 2026
CVE-2025-13959: Filestack <= 2.0.8 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
CVE-2025-13959 affects the Filepicker Media Uploader plugin (up to 2.0.8) with a CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability, so ensure you update to the patched version to mitigate risks.
March 18, 2026
CVE-2026-1714: ShopLentor <= 3.3.2 Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action PoC, Patch Analysis & Rule
CVE-2026-1714 affects the Woolentor Addons plugin for WordPress (up to version 3.3.2), allowing unauthenticated email relay abuse. Patch to version 3.3.3 to mitigate this high-severity vulnerability with a CVSS score of 8.6.
March 18, 2026
CVE-2025-6460: Display During Conditional Shortcode <= 1.2 Authenticated (Contributor+) Stored Cross-Site Scripting via message Parameter PoC, Patch Analysis & Rule
CVE-2025-6460 affects the Display During Conditional Shortcode plugin (up to v1.2) with a medium severity (CVSS 6.4) XSS vulnerability. Update to v1.3 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026
CVE-2026-1277: URL Shortify <= 1.12.1 Unauthenticated Open Redirect via 'redirect_to' Parameter PoC, Patch Analysis & Rule
CVE-2026-1277 affects the Url Shortify plugin for WordPress (versions
March 18, 2026
CVE-2026-2576: Business Directory Plugin <= 6.4.21 Unauthenticated SQL Injection via payment Parameter PoC, Patch Analysis & Rule
CVE-2026-2576 affects the Business Directory Plugin for WordPress (up to version 6.4.21) with a CVSS score of 7.5. Patch to version 6.4.22 to mitigate this high-severity SQL injection vulnerability.
March 18, 2026
CVE-2026-3075: Simple Ajax Chat <= 20251121 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
CVE-2026-3075 affects the Simple Ajax Chat plugin (up to version 20251121) with a CVSS score of 5.3. Unauthenticated attackers can access sensitive user data. Update to version 20260217 to mitigate this risk.
March 18, 2026
CVE-2026-1931: Rent Fetch <= 0.32.4 Unauthenticated Stored Cross-Site Scripting via 'keyword' Parameter PoC, Patch Analysis & Rule
CVE-2026-1931 affects the Rentfetch plugin (up to v0.32.6) with a high severity CVSS of 7.2 due to stored XSS. Users should update to v0.32.7 to mitigate risks from unauthenticated script injections.
March 18, 2026
CVE-2026-2230: Booking Calendar <= 10.14.14 Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification PoC, Patch Analysis & Rule
CVE-2026-2230 affects the Booking Calendar plugin (up to v10.14.14) with a medium severity (CVSS 4.3) IDOR vulnerability. Authenticated users can alter others' settings, so update to v10.14.15 to mitigate risks.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
