
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2025-14608: WP Last Modified Info <= 1.9.5 Insecure Direct Object Reference to Authenticated (Author+) Post Metadata Modification PoC, Patch Analysis & Rule
CVE-2025-14608 affects the WP Last Modified Info plugin (up to 1.9.5) with a medium severity (CVSS 5.3) vulnerability. Patch to version 1.9.6 to prevent unauthorized metadata modifications by authenticated users.
March 18, 2026
CVE-2026-1841: PixelYourSite <= 11.2.0 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-1841 affects the PixelYourSite plugin (up to v11.2.0) with a CVSS score of 7.2, allowing stored XSS attacks. Users should update to v11.2.0.1 to mitigate this high-severity vulnerability.
March 18, 2026
CVE-2026-1320: Secure Copy Content Protection and Content Locking <= 4.9.8 Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header PoC, Patch Analysis & Rule
CVE-2026-1320 affects the Secure Copy Content Protection plugin (up to v4.9.8) with a high severity CVSS score of 7.2 due to stored XSS. Update to v4.9.9 to mitigate risks from unauthorized script injections.
March 18, 2026
CVE-2026-1316: Customer Reviews for WooCommerce <= 5.97.0 Unauthenticated Stored Cross-Site Scripting via media[].href Parameter PoC, Patch Analysis & Rule
CVE-2026-1316 affects the Customer Reviews for WooCommerce plugin (up to v5.97.0) with a high severity CVSS score of 7.2. Patch to v5.98.0 to mitigate stored XSS risks from unauthenticated attackers.
March 18, 2026
CVE-2026-1671: Activity Log for WordPress <= 1.2.8 Missing Authorization to Sensitive Information Exposure via Log File PoC, Patch Analysis & Rule
CVE-2026-1671 affects the Winterlock plugin (up to 1.2.8) with a CVSS score of 6.5. It allows authenticated users to access sensitive data due to a missing capability check. Update to the patched version to mitigate this risk.
March 18, 2026
CVE-2026-1356: Converter for Media – Optimize images | Convert WebP & AVIF <= 6.5.1 Unauthenticated Server-Side Request Forgery via src PoC, Patch Analysis & Rule
CVE-2026-1356 affects the Webp Converter For Media plugin (up to v6.5.1) with a medium severity CVSS score of 4.8. Unauthenticated SSRF vulnerabilities can lead to unauthorized access to internal services; patching is essential.
March 18, 2026
CVE-2025-69394: Cnvrse <= 026.02.10.20 Unauthenticated Insecure Direct Object Reference PoC, Patch Analysis & Rule
CVE-2025-69394 affects the Cnvrse WordPress plugin (up to version 026.02.10.20) with a medium severity (CVSS 5.3) vulnerability. Unauthenticated attackers can exploit this IDOR issue; ensure you update to the patched version.
March 18, 2026
CVE-2026-1537: LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 Missing Authorization to Booking Details Exposure PoC, Patch Analysis & Rule
CVE-2026-1537 affects the LatePoint plugin (up to v5.2.6) with a medium severity score of 5.3. Unauthenticated attackers can access sensitive booking data. Update to v5.2.7 to mitigate this vulnerability.
March 18, 2026
CVE-2026-25036: Passster <= 4.2.25 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-25036 affects the Content Protector plugin for WordPress (up to version 4.2.25) with a medium severity CVSS score of 4.3. Ensure you update to version 4.2.26 to mitigate unauthorized access risks.
March 18, 2026
CVE-2025-68501: Mollie Payments for WooCommerce <= 8.1.1 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-68501 affects the Mollie Payments for WooCommerce plugin (up to version 8.1.1) with a medium severity CVSS score of 6.1. Users should upgrade to version 8.1.2 to mitigate the reflected XSS vulnerability.
March 18, 2026
CVE-2025-68495: JetEngine <= 3.8.0 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-68495 affects the Jet Engine plugin for WordPress (up to 3.8.0) with a CVSS score of 6.1. This medium-severity reflected XSS vulnerability can be exploited by unauthenticated attackers, making it crucial to patch or mitigate.
March 18, 2026
CVE-2026-1787: LearnPress Export Import <= 4.1.0 Missing Authentication to Unauthenticated Migrated Course Deletion PoC, Patch Analysis & Rule
CVE-2026-1787 affects the LearnPress Import Export plugin (up to 4.1.0) with a CVSS score of 4.8. Unauthenticated attackers can delete migrated courses when Tutor LMS is active. Update to version 4.1.1 to mitigate this risk.
March 18, 2026
CVE-2026-2608: Gutenberg Blocks by Kadence Blocks <= 3.5.32 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-2608 affects the Kadence Blocks plugin (up to 3.5.32) with a medium severity CVSS score of 4.3. Authenticated attackers can exploit this flaw to perform unauthorized actions. Update to version 3.6.0 to mitigate risks.
March 18, 2026
CVE-2026-22352: Persian Woocommerce SMS <= 7.1.1 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-22352 affects the Persian Woocommerce SMS plugin (up to 7.1.1) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Users should update to the patched version to mitigate potential script injection risks.
March 18, 2026
CVE-2026-24959: JS Help Desk <= 3.0.1 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-24959 affects the JS Support Ticket plugin (up to 3.0.1) with a medium severity SQL injection vulnerability (CVSS 6.5). Update to version 3.0.2 to mitigate risks from authenticated attackers exploiting this flaw.
March 18, 2026
CVE-2025-68514: Paid Member Subscriptions <= 2.16.8 Authenticated (Subscriber+) Insecure Direct Object Reference PoC, Patch Analysis & Rule
CVE-2025-68514 affects the Paid Member Subscriptions plugin (up to 2.16.8) with a medium severity (CVSS 4.3) vulnerability. Update to version 2.16.9 to mitigate unauthorized actions by authenticated users.
March 18, 2026
CVE-2026-22351: FullCalendar <= 1.6 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-22351 affects the Wp Fullcalendar plugin (up to version 1.6) with a medium severity score of 5.3. Unauthenticated attackers can exploit this flaw for unauthorized actions. Ensure you update to the patched version.
March 18, 2026
CVE-2025-69063: New User Approve <= 3.2.0 Missing Authorization PoC, Patch Analysis & Rule
CVE-2025-69063 affects the New User Approve plugin for WordPress, versions up to 3.2.0, with a medium severity CVSS score of 5.3. Update to version 3.2.1 to mitigate unauthorized access risks.
March 18, 2026
CVE-2025-68534: PDF for WPForms <= 6.3.0 Missing Authorization PoC, Patch Analysis & Rule
CVE-2025-68534 affects the PDF for WPForms plugin (up to v6.3.0) with a medium severity CVSS score of 4.3. Authenticated attackers can exploit this flaw for unauthorized actions. Users should update to the patched version for protection.
March 18, 2026
CVE-2026-22350: PDF for Elementor Forms + Drag And Drop Template Builder <= 6.3.1 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-22350 affects the PDF for Elementor Forms plugin (up to v6.3.1) with a medium severity (CVSS 4.3) vulnerability. Update to v6.5.0 to mitigate unauthorized actions by authenticated users.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
