
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-22357: Link Whisper Free <= 0.9.0 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-22357 affects the Link Whisper plugin for WordPress (up to version 0.9.0) with a medium severity CVSS score of 6.1. Users should update to version 0.9.1 to mitigate the reflected XSS vulnerability.
March 18, 2026
CVE-2026-1793: Element Pack Addons for Elementor <= 8.3.17 Authenticated (Contributor+) Arbitrary File Read PoC, Patch Analysis & Rule
CVE-2026-1793 affects Bdthemes Element Pack Lite plugin (up to v8.3.17) with a CVSS of 6.5. Authenticated users can exploit a file upload vulnerability to read sensitive server files. Update to v8.3.18 to mitigate this risk.
March 18, 2026
CVE-2026-22356: Jetpack CRM <= 6.7.0 Unauthenticated Local File Inclusion PoC, Patch Analysis & Rule
CVE-2026-22356 affects the Zero Bs Crm plugin (up to v6.7.0) with a high severity CVSS score of 8.1. This authentication bypass vulnerability allows unauthenticated attackers to execute arbitrary PHP code. Upgrade to v6.7.1 to mitigate...
March 18, 2026
CVE-2026-25362: FooGallery <= 3.1.11 Authenticated (Author+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-25362 affects the FooGallery plugin for WordPress (up to version 3.1.11) with a medium severity CVSS score of 6.4. Users should update to version 3.1.13 to mitigate the risk of stored XSS attacks.
March 18, 2026
CVE-2026-1750: Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access PoC, Patch Analysis & Rule
CVE-2026-1750 affects the Ecwid Shopping Cart plugin (up to version 7.0.7) with a CVSS score of 8.8. This high-severity remote code execution vulnerability allows low-privilege users to gain store manager access. Update to version 7.0.8.
March 18, 2026
CVE-2026-25364: Client Invoicing by Sprout Invoices <= 20.8.8 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-25364 affects the Sprout Invoices plugin (up to version 20.8.8) with a medium severity score of 5.3. Unauthenticated attackers can exploit this vulnerability to manipulate invoice data. Update to version 20.8.9 to mitigate risks.
March 18, 2026
CVE-2026-25348: Download Alt Text AI <= 1.10.15 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-25348 affects the Alttext Ai plugin for WordPress (up to version 1.10.15) with a medium severity CVSS score of 5.3. Ensure you update to version 1.10.18 to mitigate unauthorized access risks.
March 18, 2026
CVE-2026-1490: Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation PoC, Patch Analysis & Rule
CVE-2026-1490 affects the Cleantalk Spam Protect plugin (up to v6.71) with a critical CVSS score of 9.8. This authentication bypass allows unauthorized plugin installations. Update to v6.72 to mitigate the risk.
March 18, 2026
CVE-2026-1512: Essential Addons for Elementor <= 6.5.9 Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget PoC, Patch Analysis & Rule
CVE-2026-1512 affects the Essential Addons for Elementor Lite plugin (up to v6.5.9) with a medium severity CVSS score of 6.4. Patch to v6.5.10 to mitigate stored XSS risks from authenticated users injecting scripts.
March 18, 2026
CVE-2026-25331: Activity Log <= 5.5.4 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-25331 affects the Wp Security Audit Log plugin (up to 5.5.4) with a medium severity (CVSS 6.4) stored XSS vulnerability. Update to version 5.6.0 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026
CVE-2026-2312: Media Library Folders <= 8.3.6 Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Attachment Deletion and Rename PoC, Patch Analysis & Rule
CVE-2026-2312 affects the Media Library Plus plugin (up to v8.3.6) with a CVSS score of 4.3. Authenticated users can delete or rename attachments of others. Upgrade to v8.3.7 to mitigate this risk.
March 18, 2026
CVE-2026-1249: MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 5.3 5.10 Authenticated (Author+) Server-Side Request Forgery PoC, Patch Analysis & Rule
CVE-2026-1249 affects the Mp3 Music Player by Sonaar plugin (versions 5.3 to 5.10) with a medium severity CVSS score of 5.0. Users should upgrade to version 5.11 to mitigate the Server-Side Request Forgery risk.
March 18, 2026
CVE-2026-1843: Super Page Cache <= 5.2.2 Unauthenticated Stored Cross-Site Scripting via Activity Log PoC, Patch Analysis & Rule
CVE-2026-1843 affects the Wp Cloudflare Page Cache plugin (up to version 5.2.2) with a high severity XSS vulnerability (CVSS 7.2). Users should update to version 5.2.3 to mitigate risks from potential script injections.
March 18, 2026
CVE-2025-8572: Truelysell Core <= 1.8.7 Unauthenticated Privilege Escalation via Registration PoC, Patch Analysis & Rule
CVE-2025-8572 affects the Truelysell Core plugin (versions
March 18, 2026
CVE-2026-1254: Modula Image Gallery – Photo Grid & Video Gallery <= 2.13.6 Missing Authorization to Authenticated (Contributor+) Arbitrary Post/Page Editing PoC, Patch Analysis & Rule
CVE-2026-1254 affects the Modula Best Grid Gallery plugin (up to 2.13.6) with a medium severity CVSS of 4.3. Authenticated users can bypass authorization to modify posts. Upgrade to 2.13.7 to mitigate this risk.
March 18, 2026
CVE-2025-15483: Link Hopper <= 2.5 Authenticated (Administrator+) Stored Cross-Site Scripting via 'hop_name' Parameter PoC, Patch Analysis & Rule
CVE-2025-15483 affects the Link Hopper plugin (up to v2.5) with a medium severity CVSS score of 4.4. Authenticated attackers can exploit stored XSS vulnerabilities, emphasizing the need for prompt patching in multi-site setups.
March 18, 2026
CVE-2026-0550: myCred <= 2.9.7.3 Authenticated (Contributor+) Stored Cross-Site Scripting via 'mycred_load_coupon' Shortcode PoC, Patch Analysis & Rule
CVE-2026-0550 affects the myCred WordPress plugin (up to version 2.9.7.3) with a medium severity XSS vulnerability. Users should upgrade to version 2.9.7.4 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026
CVE-2026-1258: Mail Mint <= 1.19.2 Authenticated (Administrator+) SQL Injection via Multiple API Endpoints PoC, Patch Analysis & Rule
CVE-2026-1258 affects the Mail Mint plugin (up to v1.19.2) with a CVSS score of 4.9. Administrators should upgrade to v1.19.3 to mitigate SQL injection risks from multiple API endpoints.
March 18, 2026
CVE-2026-1792: Geo Widet <= 1.0 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-1792 affects the Geo Widget plugin for WordPress (version 1.0) with a medium severity CVSS score of 6.1. Unauthenticated attackers can exploit this stored XSS vulnerability. Ensure you patch to mitigate risks.
March 18, 2026
CVE-2026-1306: midi-Synth <= 1.1.0 Unauthenticated Arbitrary File Upload via 'export' AJAX Action PoC, Patch Analysis & Rule
CVE-2026-1306 affects the Midi Synth plugin for WordPress, with a critical CVSS score of 9.8. Unauthenticated attackers can exploit a file upload vulnerability. Update to the patched version to mitigate risks.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
