
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-0557: WP Data Access <= 5.5.63 Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpda_app' Shortcode PoC, Patch Analysis & Rule
CVE-2026-0557 affects the WP Data Access plugin (up to version 5.5.63) with a CVSS score of 6.4. Authenticated users can exploit this stored XSS vulnerability. Update to version 5.5.64 to mitigate risks.
March 18, 2026
CVE-2026-0693: Allow HTML in Category Descriptions <= 1.2.4 Authenticated (Administrator+) Stored Cross-Site Scripting via Category Descriptions PoC, Patch Analysis & Rule
CVE-2026-0693 affects the Allow HTML in Category Descriptions plugin (up to v1.2.4) with a medium severity (CVSS 4.4) XSS vulnerability. Update to v1.2.5 to mitigate risks from authenticated attacks.
March 18, 2026
CVE-2025-6792: One to one user Chat by WPGuppy <= 1.1.4 Unauthenticated Information Disclosure via Chat Message Interception PoC, Patch Analysis & Rule
CVE-2025-6792 affects Wpguppy Lite plugin versions up to 1.1.4, allowing unauthenticated users to access private chat messages. Upgrade to 1.1.5 to mitigate this medium severity vulnerability.
March 18, 2026
CVE-2026-1187: ZoomifyWP Free <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'filename' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1187 affects the Tz Zoomifywp Free plugin (v1.1) with a CVSS score of 6.4. This medium severity stored XSS vulnerability allows authenticated attackers to inject scripts. Users should update to the patched version to mitigate...
March 18, 2026
CVE-2026-1932: Appointment Booking Calendar Plugin <= 1.0.2 Missing Authorization to Unauthenticated Arbitrary Appointment Status Modification PoC, Patch Analysis & Rule
CVE-2026-1932 affects the Bookr plugin for WordPress (up to v1.0.2) with a CVSS score of 5.3. Unauthenticated attackers can modify appointment statuses; patching is crucial to mitigate this risk.
March 18, 2026
CVE-2026-2024: PhotoStack Gallery <= 0.4.1 Unauthenticated SQL Injection via 'postid' Parameter PoC, Patch Analysis & Rule
CVE-2026-2024 affects the PhotoStack Gallery plugin (up to v0.4.1) with a CVSS score of 7.5. This high-severity SQL injection allows unauthenticated attackers to access sensitive database information. Patching is essential.
March 18, 2026
CVE-2026-1754: personal-authors-category <= 0.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-1754 affects the Personal Authors Category plugin for WordPress (up to v0.3) with a medium severity (CVSS 6.1) XSS vulnerability. Ensure you patch to mitigate risks from potential script injections.
March 18, 2026
CVE-2026-1915: Simple Plyr <= 0.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'poster' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1915 affects the Simple Plyr plugin (v0.0.1) with a medium severity score of 6.4. Authenticated users can exploit this cross-site scripting vulnerability, so ensure you update to the patched version to mitigate risks.
March 18, 2026
CVE-2026-2144: Magic Login Mail or QR Code <= 2.05 Unauthenticated Privilege Escalation via Insecure QR Code File Storage PoC, Patch Analysis & Rule
CVE-2026-2144 affects the Magic Login Mail plugin (v2.05) with a CVSS score of 8.1. This high-severity vulnerability allows unauthenticated attackers to exploit a race condition for privilege escalation. Patching is essential.
March 18, 2026
CVE-2026-1904: Simple Wp colorfull Accordion <= 1.0 Authenticated (Contributor+) Cross-Site Scripting via 'title' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1904 affects the Simple Wp Colorfull Accordion plugin (up to v1.0) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should patch to prevent authenticated attackers from injecting scripts.
March 18, 2026
CVE-2026-2027: AMP Enhancer <= 1.0.49 Authenticated (Administrator+) Stored Cross-Site Scripting via AMP Custom CSS Setting PoC, Patch Analysis & Rule
CVE-2026-2027 affects the Amp Enhancer plugin (up to v1.0.49) with a CVSS score of 4.4. This medium-severity XSS vulnerability allows authenticated admins to inject scripts. Patch to mitigate risks.
March 18, 2026
CVE-2026-1983: SEATT: Simple Event Attendance <= 1.5.0 Cross-Site Request Forgery to Arbitrary Event Deletion PoC, Patch Analysis & Rule
CVE-2026-1983 affects the Simple Event Attendance plugin for WordPress (up to version 1.5.0) with a medium severity CVSS score of 4.3. Patching is crucial to prevent unauthenticated event deletions via CSRF attacks.
March 18, 2026
CVE-2026-0692: BlueSnap Payment Gateway for WooCommerce <= 3.4.0 Missing Authorization to Unauthenticated Arbitrary Order Status Manipulation PoC, Patch Analysis & Rule
CVE-2026-0692 affects the BlueSnap Payment Gateway for WooCommerce plugin (up to version 3.4.0) with a CVSS score of 7.5. Patch to version 3.4.1 to mitigate unauthorized order status manipulation.
March 18, 2026
CVE-2025-13973: StickEasy Protected Contact Form <= 1.0.1 Unauthenticated Information Disclosure PoC, Patch Analysis & Rule
CVE-2025-13973 affects the Stickeasy Protected Contact Form plugin (up to 1.0.1) with a medium severity CVSS score of 5.3. Update to 1.0.2 to mitigate sensitive information disclosure risks.
March 18, 2026
CVE-2025-15157: Starfish Review Generation & Marketing for WordPress <= 3.1.19 Authenticated (Subscriber+) Arbitrary Options Update via srm_restore_options_defaults PoC, Patch Analysis & Rule
CVE-2025-15157 affects the Starfish Reviews plugin (up to v3.1.19) with a CVSS score of 8.8. This high-severity vulnerability allows authenticated users to escalate privileges. Upgrade to v3.1.20 to mitigate risks.
March 18, 2026
CVE-2026-1912: Citations tools <= 0.3.2 Authenticated (Contributor+) Stored Cross-Site Scripting via 'code' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1912 affects the Citations Tools plugin for WordPress (up to v0.3.2) with a CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability, making it crucial to update to the patched version.
March 18, 2026
CVE-2025-13681: BFG Tools – Extension Zipper <= 1.0.7 Authenticated (Administrator+) Path Traversal via 'first_file' Parameter PoC, Patch Analysis & Rule
CVE-2025-13681 affects the BFG Tools Extension Zipper plugin (up to v1.0.7) with a medium severity (CVSS 4.9) path traversal vulnerability. Update to v1.0.8 to mitigate the risk of unauthorized file access.
March 18, 2026
CVE-2026-1164: Easy Voice Mail <= 1.2.5 Unauthenticated Stored Cross-Site Scripting via 'message' PoC, Patch Analysis & Rule
CVE-2026-1164 affects the Easy Voice Mail plugin (up to v1.2.5) with a medium severity CVSS score of 6.1. Admin-level users can exploit a stored XSS vulnerability, making timely patching essential for security.
March 18, 2026
CVE-2025-14067: Easy Form Builder <= 3.9.3 Missing Authorization to Authenticated (Subscriber+) Sensitive Form Response Data Exposure PoC, Patch Analysis & Rule
CVE-2025-14067 affects the Easy Form Builder plugin (up to version 3.9.3) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized data access. Users should update to version 3.9.4 to mitigate this risk.
March 18, 2026
CVE-2026-1844: PixelYourSite PRO <= 12.4.0.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-1844 affects the PixelYourSite Pro plugin (up to version 12.4.0.2) with a high severity CVSS of 7.2 due to stored XSS vulnerabilities. Users should update to the patched version to mitigate potential attacks.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
