Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-1906: PDF Invoices & Packing Slips for WooCommerce <= 5.6.0 Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification PoC, Patch Analysis & Rule

CVE-2026-1906 affects WooCommerce PDF Invoices & Packing Slips plugin versions up to 5.6.0. This medium severity vulnerability allows authenticated attackers to modify customer identifiers, impacting order routing. Upgrade to 5.7.0 to...
March 18, 2026

CVE-2026-2023: WP Plugin Info Card <= 6.2.0 Cross-Site Request Forgery to Arbitrary Custom Plugin Entry Creation PoC, Patch Analysis & Rule

CVE-2026-2023 affects the WP Plugin Info Card plugin (up to version 6.2.0) with a medium severity CVSS score of 4.3. Unauthenticated attackers can exploit this CSRF vulnerability; update to version 6.3.0 to mitigate.
March 18, 2026

CVE-2026-1639: Taskbuilder <= 5.0.2 Authenticated (Subscriber+) SQL Injection via 'order' and 'sort_by' Parameters PoC, Patch Analysis & Rule

CVE-2026-1639 affects the Taskbuilder plugin (up to v5.0.2) with a medium severity SQL injection vulnerability (CVSS 6.5). Users should upgrade to v5.0.3 to mitigate risks from authenticated attacks.
March 18, 2026

CVE-2025-11737: VK All in One Expansion Unit <= 9.112.3 Authenticated (Contributor+) Stored Cross-Site Scripting via SNS Title PoC, Patch Analysis & Rule

CVE-2025-11737 affects the VK All In One Expansion Unit plugin for WordPress (up to 9.112.3) with a CVSS score of 6.4. Authenticated attackers can exploit this medium severity XSS vulnerability, so ensure prompt patching.
March 18, 2026

CVE-2025-12071: Frontend User Notes <= 2.1.0 Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Note Modification PoC, Patch Analysis & Rule

CVE-2025-12071 affects the Frontend User Notes plugin for WordPress (up to 2.1.0) with a CVSS score of 4.3. Authenticated users can modify others' notes. Upgrade to version 2.1.1 to mitigate this risk.
March 18, 2026

CVE-2025-12122: Popup Box – Easily Create WordPress Popups <= 3.2.12 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-12122 affects the Popup Box plugin (up to v3.2.12) with a medium severity CVSS score of 6.4. Authenticated users can exploit this XSS vulnerability, so update to v3.2.13 to mitigate risks.
March 18, 2026

CVE-2026-1304: Membership Plugin – Restrict Content <= 3.2.18 Authenticated (Administrator+) Stored Cross-Site Scripting via Invoice Settings PoC, Patch Analysis & Rule

CVE-2026-1304 affects the Restrict Content plugin (up to v3.2.18) with a medium severity CVSS score of 4.4. Admins should upgrade to v3.2.19 to mitigate the stored XSS risk from insufficient input sanitization.
March 18, 2026

CVE-2025-12075: Order Splitter for WooCommerce <= 5.3.5 Missing Authorization to Authenticated (Subscriber+) Order Information Exposure PoC, Patch Analysis & Rule

CVE-2025-12075 affects the Woo Order Splitter plugin (up to v5.3.5) with a medium severity (CVSS 4.3) vulnerability allowing authenticated users to access sensitive order data. Update to v5.3.6 to mitigate this risk.
March 18, 2026

CVE-2026-1925: EmailKit – Email Customizer for WooCommerce & WP <= 1.6.2 Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Title Modification PoC, Patch Analysis & Rule

CVE-2026-1925 affects the Emailkit plugin (up to v1.6.2) with a CVSS score of 4.3, allowing authenticated users to modify post titles. Upgrade to v1.6.3 to mitigate this remote code execution risk.
March 18, 2026

CVE-2025-12037: WP 404 Auto Redirect <= 1.0.5 Authenticated (Admin+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-12037 affects the WP 404 Auto Redirect to Similar Post plugin (up to v1.0.5) with a CVSS score of 4.4. Administrators should update to v1.0.6 to mitigate the stored XSS vulnerability.
March 18, 2026

CVE-2026-1296: Frontend Post Submission Manager Lite <= 1.2.7 Unauthenticated Open Redirect via 'requested_page' Parameter PoC, Patch Analysis & Rule

CVE-2026-1296 affects Frontend Post Submission Manager Lite versions up to 1.2.7 with a medium severity (CVSS 6.1) open redirection vulnerability. Upgrade to 1.2.8 to mitigate risks of user redirection to malicious sites.
March 18, 2026

CVE-2025-13959: Filestack <= 2.0.8 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2025-13959 affects the Filepicker Media Uploader plugin (up to 2.0.8) with a CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability, so ensure you update to the patched version to mitigate risks.
March 18, 2026

CVE-2026-1714: ShopLentor <= 3.3.2 Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action PoC, Patch Analysis & Rule

CVE-2026-1714 affects the Woolentor Addons plugin for WordPress (up to version 3.3.2), allowing unauthenticated email relay abuse. Patch to version 3.3.3 to mitigate this high-severity vulnerability with a CVSS score of 8.6.
March 18, 2026

CVE-2025-6460: Display During Conditional Shortcode <= 1.2 Authenticated (Contributor+) Stored Cross-Site Scripting via message Parameter PoC, Patch Analysis & Rule

CVE-2025-6460 affects the Display During Conditional Shortcode plugin (up to v1.2) with a medium severity (CVSS 6.4) XSS vulnerability. Update to v1.3 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026

CVE-2026-2576: Business Directory Plugin <= 6.4.21 Unauthenticated SQL Injection via payment Parameter PoC, Patch Analysis & Rule

CVE-2026-2576 affects the Business Directory Plugin for WordPress (up to version 6.4.21) with a CVSS score of 7.5. Patch to version 6.4.22 to mitigate this high-severity SQL injection vulnerability.
March 18, 2026

CVE-2026-3075: Simple Ajax Chat <= 20251121 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

CVE-2026-3075 affects the Simple Ajax Chat plugin (up to version 20251121) with a CVSS score of 5.3. Unauthenticated attackers can access sensitive user data. Update to version 20260217 to mitigate this risk.
March 18, 2026

CVE-2026-1931: Rent Fetch <= 0.32.4 Unauthenticated Stored Cross-Site Scripting via 'keyword' Parameter PoC, Patch Analysis & Rule

CVE-2026-1931 affects the Rentfetch plugin (up to v0.32.6) with a high severity CVSS of 7.2 due to stored XSS. Users should update to v0.32.7 to mitigate risks from unauthenticated script injections.
March 18, 2026

CVE-2026-2230: Booking Calendar <= 10.14.14 Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification PoC, Patch Analysis & Rule

CVE-2026-2230 affects the Booking Calendar plugin (up to v10.14.14) with a medium severity (CVSS 4.3) IDOR vulnerability. Authenticated users can alter others' settings, so update to v10.14.15 to mitigate risks.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works