Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2025-15400: OpenPix <= 2.13.3 Missing Authorization to Authenticated (Subscriber+) Settings Update PoC, Patch Analysis & Rule

CVE-2025-15400 affects the OpenPix for WooCommerce plugin (up to v2.13.3) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized actions by authenticated users. Upgrade to v2.13.4 to mitigate this risk.
March 18, 2026

CVE-2026-24956: Download Manager Addons for Elementor <= 1.3.0 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2026-24956 affects the Wpdm Elementor plugin (up to 1.3.0) with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated attackers to access sensitive data. Patch immediately.
March 18, 2026

CVE-2026-22346: Slider Responsive Slideshow – Image slider, Gallery slideshow <= 1.5.4 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule

CVE-2026-22346 affects the Slider Responsive Slideshow plugin (v1.5.4) with a CVSS score of 7.5. Authenticated attackers can exploit a file upload vulnerability, leading to potential code execution. Patching is essential for security.
March 18, 2026

CVE-2026-1104: FastDup – Fastest WordPress Migration & Duplicator <= 2.7.1 Missing Authorization to Authenticated (Contributor+) Backup Creation and Download PoC, Patch Analysis & Rule

CVE-2026-1104 affects the Fastdup plugin (up to v2.7.1) with a high severity CVSS score of 8.8. Authenticated users can exploit this to create unauthorized full-site backups. Update to v2.7.2 to mitigate this risk.
March 18, 2026

CVE-2025-69401: WooODT Lite <= 2.5.2 Unauthenticated Payment Bypass PoC, Patch Analysis & Rule

CVE-2025-69401 affects the Byconsole Woo Order Delivery Time plugin (up to v2.5.2) with a medium severity score of 5.3. Unauthenticated attackers can bypass payments, so ensure you update to the patched version.
March 18, 2026

CVE-2025-69392: iMoney <= 0.36 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-69392 affects the iMoney WordPress plugin (up to version 0.36) with a medium severity CVSS score of 6.1. Users should update to the patched version to mitigate the risk of reflected XSS attacks.
March 18, 2026

CVE-2025-69403: Bravis Addons <= 1.1.9 Authenticated (Subscriber+) Arbitrary File Upload PoC, Patch Analysis & Rule

CVE-2025-69403 affects the Bravis Addons plugin for WordPress, with a high CVSS score of 8.8. Authenticated users can exploit a file upload vulnerability, risking remote code execution. Update to the patched version to mitigate.
March 18, 2026

CVE-2025-68526: Modal Popup Box <= 1.6.1 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule

CVE-2025-68526 affects the Modal Popup Box plugin for WordPress (up to version 1.6.1) with a high severity CVSS score of 7.5. Authenticated attackers can exploit this file upload vulnerability; update to version 1.6.2 to mitigate risks.
March 18, 2026

CVE-2026-2295: WPZOOM Addons for Elementor – Starter Templates & Widgets <= 1.3.2 Unauthenticated Protected Post Exposure via ajax_post_grid_load_more PoC, Patch Analysis & Rule

CVE-2026-2295 affects WPZOOM Elementor Addons plugin version 1.3.2, allowing unauthorized access to draft and pending post data. Upgrade to version 1.3.3 to mitigate this medium-severity vulnerability.
March 18, 2026

CVE-2025-15096: Videospirecore Theme Plugin <= 1.0.6 Authenticated (Subscriber+) Privilege Escalation via User Email Change/Account Takeover PoC, Patch Analysis & Rule

CVE-2025-15096 affects the Videospirecore plugin for WordPress, allowing authenticated attackers to escalate privileges and take over accounts. With a CVSS score of 8.8, users should update to the patched version to mitigate this risk.
March 18, 2026

CVE-2026-22345: Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery <= 1.6.0 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule

CVE-2026-22345 affects the New Image Gallery plugin for WordPress (up to 1.6.0) with a high severity CVSS score of 7.5. Patch to version 1.6.1 to mitigate the risk of PHP Object Injection by authenticated users.
March 18, 2026

CVE-2026-1853: BuddyHolis ListSearch <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'placeholder' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-1853 affects the Listsearch plugin for WordPress (up to v1.1) with a CVSS score of 6.4. This medium-severity XSS vulnerability allows authenticated attackers to inject scripts. Users should update to the patched version to...
March 18, 2026

CVE-2026-1748: Invoct – PDF Invoices & Billing for WooCommerce <= 1.6 Missing Authorization to Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule

CVE-2026-1748 affects the Kirilkirkov Pdf Invoice Manager plugin (up to v1.6) with a CVSS score of 4.3. Authenticated users can exploit this remote code execution flaw to access sensitive data. Upgrade to v1.7 to mitigate risks.
March 18, 2026

CVE-2026-1804: WDES Responsive Popup <= 1.3.6 Authenticated (Contributor+) Stored Cross-Site Scripting via 'attr' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-1804 affects the Wdes Responsive Popup plugin (up to v1.3.6) with a medium severity (CVSS 6.4) stored XSS vulnerability. Authenticated attackers can inject scripts, impacting user security. Ensure you update to the patched version.
March 18, 2026

CVE-2026-1827: IDE Micro code-editor <= 1.0.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-1827 affects the Flask Micro plugin for WordPress (up to version 1.0.0) with a CVSS score of 6.4. Authenticated users can exploit this XSS vulnerability, so patching is crucial to prevent script injection.
March 18, 2026

CVE-2026-1215: MMA Call Tracking <= 2.3.15 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule

CVE-2026-1215 affects the MMA Call Tracking plugin for WordPress (up to version 2.3.15) with a medium severity CVSS score of 4.3. Ensure to patch to prevent unauthorized configuration changes via CSRF attacks.
March 18, 2026

CVE-2026-0724: WPlyr Media Block <= 1.3.0 Authenticated (Administrator+) Stored Cross-Site Scripting via '_wplyr_accent_color' Parameter PoC, Patch Analysis & Rule

CVE-2026-0724 affects the WPlyr Media Block plugin (up to v1.3.0) with a CVSS score of 4.4. Authenticated attackers can exploit stored XSS vulnerabilities. Patching is recommended to mitigate risks.
March 18, 2026

CVE-2025-15440: iONE360 configurator <= 2.0.57 Unauthenticated Stored Cross-Site Scripting via Contact Form Parameters PoC, Patch Analysis & Rule

CVE-2025-15440 affects the Ione360 Configurator plugin for WordPress (up to version 2.0.57) with a CVSS score of 7.2. Unauthenticated stored XSS can be exploited via contact form parameters; patching is essential.
March 18, 2026

CVE-2026-1885: Slideshow Wp <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'sswp-slide' Shortcode 'sswpid' Attribute PoC, Patch Analysis & Rule

CVE-2026-1885 affects the Slideshow Wp plugin (up to version 1.1) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability, so ensure you update to the patched version.
March 18, 2026

CVE-2026-1809: HTML Shortcodes <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2026-1809 affects the Html Shortcodes plugin for WordPress, with a CVSS score of 6.4. Users should update to the patched version to mitigate the risk of stored XSS attacks from authenticated users.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works