Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2025-14799: Brevo Email, SMS, Web Push, Chat, and more. <= 3.3.0 Unauthenticated Authorization Bypass via Type Juggling PoC, Patch Analysis & Rule

CVE-2025-14799 affects the Mailin plugin for WordPress (up to version 3.3.0) with a medium severity CVSS score of 6.5. Unauthenticated attackers can bypass authorization, making it crucial to update to version 3.3.1.
March 18, 2026

CVE-2026-25370: Compress <= 6.60.28 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-25370 affects the Wp Compress Image Optimizer plugin (up to version 6.60.28) with a CVSS score of 5.3. Unauthenticated attackers can exploit this to perform unauthorized actions. Update to version 6.60.29 to mitigate risks.
March 18, 2026

CVE-2026-1317: WP Import – Ultimate CSV XML Importer for WordPress <= 7.37 Authenticated (Subscriber+) SQL Injection via File Name PoC, Patch Analysis & Rule

CVE-2026-1317 affects WP Ultimate CSV Importer (up to v7.37) with a medium severity (CVSS 6.5) SQL injection vulnerability. Users should upgrade to v7.38 to mitigate risks from authenticated attacks.
March 18, 2026

CVE-2026-0829: Frontend File Manager <= 23.5 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-0829 affects the Nmedia User File Uploader plugin (up to version 23.5) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized file access. Update to version 23.6 to mitigate this risk.
March 18, 2026

CVE-2026-22384: Applay Shortcodes <= 3.7 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule

CVE-2026-22384 affects the Applay Shortcodes plugin (v3.7) with a high severity CVSS score of 7.5. Authenticated attackers can exploit a file upload vulnerability, making it crucial to patch or mitigate to prevent potential data loss.
March 18, 2026

CVE-2026-1216: RSS Aggregator <= 5.0.10 Reflected Cross-Site Scripting via 'template' Parameter PoC, Patch Analysis & Rule

CVE-2026-1216 affects the Wp Rss Aggregator plugin (up to version 5.0.10) with a high severity CVSS score of 7.2 due to reflected XSS. Users should upgrade to version 5.0.11 to mitigate this vulnerability.
March 18, 2026

CVE-2026-1582: WP All Export <= 1.4.14 Unauthenticated Sensitive Information Exposure via PHP Type Juggling PoC, Patch Analysis & Rule

CVE-2026-1582 affects WP All Export plugin versions up to 1.4.14, allowing unauthenticated access to sensitive data. Upgrade to 1.4.15 to mitigate this low-severity vulnerability with a CVSS score of 3.7.
March 18, 2026

CVE-2026-1657: EventPrime <= 4.2.8.4 Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint PoC, Patch Analysis & Rule

CVE-2026-1657 reveals a medium severity file upload vulnerability in the Eventprime Event Calendar Management plugin (up to 4.2.8.4). Users should upgrade to 4.2.8.5 to prevent unauthorized image uploads.
March 18, 2026

CVE-2026-2592: Zarinpal Gateway for WooCommerce <= 5.0.16 Improper Access Control to Payment Status Update PoC, Patch Analysis & Rule

CVE-2026-2592 affects Zarinpal WooCommerce Payment Gateway (up to 5.0.16) with a CVSS score of 7.7. This high-severity flaw allows unauthenticated payment status manipulation. Update to version 5.0.17 to mitigate risks.
March 18, 2026

CVE-2026-1426: Advanced AJAX Product Filters <= 3.1.9.6 Authenticated (Author+) PHP Object Injection via Live Composer Compatibility PoC, Patch Analysis & Rule

CVE-2026-1426 affects the Woocommerce Ajax Filters plugin (up to v3.1.9.6) with a high severity CVSS score of 8.8. Patch to v3.1.9.7 to mitigate the risk of PHP object injection when using Live Composer.
March 18, 2026

CVE-2025-69337: Wolmart Core <= 1.9.6 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2025-69337 affects the Wolmart Core plugin (up to version 1.9.6) with a high severity SQL injection vulnerability (CVSS 7.5). Unauthenticated attackers can exploit this to access sensitive database information. Patching is essential.
March 18, 2026

CVE-2026-2002: Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.50.2 Authenticated (Administrator+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-2002 affects the Forminator plugin (up to version 1.50.2) with a medium severity CVSS score of 4.4. Admins should patch to prevent stored XSS attacks that could compromise user data.
March 18, 2026

CVE-2025-12062: WP Maps <= 4.8.6 Authenticated (Subscriber+) Limited Local File Inclusion PoC, Patch Analysis & Rule

CVE-2025-12062 affects the WP Google Map Plugin (up to v4.8.6) with a high severity CVSS score of 8.8. Patch to v4.8.7 to mitigate the risk of authentication bypass and potential code execution.
March 18, 2026

CVE-2026-2001: WowRevenue <= 2.1.3 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation PoC, Patch Analysis & Rule

CVE-2026-2001 affects the WowRevenue plugin for WordPress (up to version 2.1.3) with a CVSS score of 8.8. Authenticated users can exploit this high-severity vulnerability to install arbitrary plugins, leading to potential remote code...
March 18, 2026

CVE-2025-8781: Bookster – WordPress Appointment Booking Plugin <= 2.1.1 Authenticated (Administrator+) SQL Injection via 'raw' PoC, Patch Analysis & Rule

CVE-2025-8781 affects the Bookster WordPress plugin (up to v2.1.1) with a medium severity score of 4.9. Administrators should upgrade to v2.2.0 to mitigate an SQL injection vulnerability that could expose sensitive data.
March 18, 2026

CVE-2025-68002: Open User Map <= 1.4.16 Authenticated (Subscriber+) Arbitrary File Download PoC, Patch Analysis & Rule

CVE-2025-68002 affects the Open User Map plugin (up to v1.4.16) with a medium severity (CVSS 6.5) path traversal vulnerability. Users should update to v1.4.17 to mitigate risks of unauthorized file access.
March 18, 2026

CVE-2026-22354: Woocommerce Category Banner Management <= 2.5.1 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule

CVE-2026-22354 affects the Banner Management For Woocommerce plugin (up to v2.5.1) with a high severity CVSS of 7.5. Authenticated attackers can exploit a PHP Object Injection vulnerability, making timely patching essential.
March 18, 2026

CVE-2026-25363: FooGallery <= 3.1.11 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-25363 affects the FooGallery plugin (up to v3.1.11) with a medium severity CVSS score of 4.3. Authenticated attackers can exploit this flaw; update to v3.1.13 to mitigate unauthorized access risks.
March 18, 2026

CVE-2026-25368: Calculated Fields Form <= 5.4.4.1 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-25368 affects the Calculated Fields Form plugin for WordPress (up to version 5.4.4.1) with a medium severity CVSS score of 4.3. Ensure you update to version 5.4.4.2 to mitigate unauthorized access risks.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works