
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2025-15400: OpenPix <= 2.13.3 Missing Authorization to Authenticated (Subscriber+) Settings Update PoC, Patch Analysis & Rule
CVE-2025-15400 affects the OpenPix for WooCommerce plugin (up to v2.13.3) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized actions by authenticated users. Upgrade to v2.13.4 to mitigate this risk.
March 18, 2026
CVE-2026-24956: Download Manager Addons for Elementor <= 1.3.0 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-24956 affects the Wpdm Elementor plugin (up to 1.3.0) with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated attackers to access sensitive data. Patch immediately.
March 18, 2026
CVE-2026-22346: Slider Responsive Slideshow – Image slider, Gallery slideshow <= 1.5.4 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
CVE-2026-22346 affects the Slider Responsive Slideshow plugin (v1.5.4) with a CVSS score of 7.5. Authenticated attackers can exploit a file upload vulnerability, leading to potential code execution. Patching is essential for security.
March 18, 2026
CVE-2026-1104: FastDup – Fastest WordPress Migration & Duplicator <= 2.7.1 Missing Authorization to Authenticated (Contributor+) Backup Creation and Download PoC, Patch Analysis & Rule
CVE-2026-1104 affects the Fastdup plugin (up to v2.7.1) with a high severity CVSS score of 8.8. Authenticated users can exploit this to create unauthorized full-site backups. Update to v2.7.2 to mitigate this risk.
March 18, 2026
CVE-2025-69401: WooODT Lite <= 2.5.2 Unauthenticated Payment Bypass PoC, Patch Analysis & Rule
CVE-2025-69401 affects the Byconsole Woo Order Delivery Time plugin (up to v2.5.2) with a medium severity score of 5.3. Unauthenticated attackers can bypass payments, so ensure you update to the patched version.
March 18, 2026
CVE-2025-69392: iMoney <= 0.36 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-69392 affects the iMoney WordPress plugin (up to version 0.36) with a medium severity CVSS score of 6.1. Users should update to the patched version to mitigate the risk of reflected XSS attacks.
March 18, 2026
CVE-2025-69403: Bravis Addons <= 1.1.9 Authenticated (Subscriber+) Arbitrary File Upload PoC, Patch Analysis & Rule
CVE-2025-69403 affects the Bravis Addons plugin for WordPress, with a high CVSS score of 8.8. Authenticated users can exploit a file upload vulnerability, risking remote code execution. Update to the patched version to mitigate.
March 18, 2026
CVE-2025-68526: Modal Popup Box <= 1.6.1 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
CVE-2025-68526 affects the Modal Popup Box plugin for WordPress (up to version 1.6.1) with a high severity CVSS score of 7.5. Authenticated attackers can exploit this file upload vulnerability; update to version 1.6.2 to mitigate risks.
March 18, 2026
CVE-2026-2295: WPZOOM Addons for Elementor – Starter Templates & Widgets <= 1.3.2 Unauthenticated Protected Post Exposure via ajax_post_grid_load_more PoC, Patch Analysis & Rule
CVE-2026-2295 affects WPZOOM Elementor Addons plugin version 1.3.2, allowing unauthorized access to draft and pending post data. Upgrade to version 1.3.3 to mitigate this medium-severity vulnerability.
March 18, 2026
CVE-2025-15096: Videospirecore Theme Plugin <= 1.0.6 Authenticated (Subscriber+) Privilege Escalation via User Email Change/Account Takeover PoC, Patch Analysis & Rule
CVE-2025-15096 affects the Videospirecore plugin for WordPress, allowing authenticated attackers to escalate privileges and take over accounts. With a CVSS score of 8.8, users should update to the patched version to mitigate this risk.
March 18, 2026
CVE-2026-22345: Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery <= 1.6.0 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
CVE-2026-22345 affects the New Image Gallery plugin for WordPress (up to 1.6.0) with a high severity CVSS score of 7.5. Patch to version 1.6.1 to mitigate the risk of PHP Object Injection by authenticated users.
March 18, 2026
CVE-2026-1853: BuddyHolis ListSearch <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'placeholder' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1853 affects the Listsearch plugin for WordPress (up to v1.1) with a CVSS score of 6.4. This medium-severity XSS vulnerability allows authenticated attackers to inject scripts. Users should update to the patched version to...
March 18, 2026
CVE-2026-1748: Invoct – PDF Invoices & Billing for WooCommerce <= 1.6 Missing Authorization to Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule
CVE-2026-1748 affects the Kirilkirkov Pdf Invoice Manager plugin (up to v1.6) with a CVSS score of 4.3. Authenticated users can exploit this remote code execution flaw to access sensitive data. Upgrade to v1.7 to mitigate risks.
March 18, 2026
CVE-2026-1804: WDES Responsive Popup <= 1.3.6 Authenticated (Contributor+) Stored Cross-Site Scripting via 'attr' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1804 affects the Wdes Responsive Popup plugin (up to v1.3.6) with a medium severity (CVSS 6.4) stored XSS vulnerability. Authenticated attackers can inject scripts, impacting user security. Ensure you update to the patched version.
March 18, 2026
CVE-2026-1827: IDE Micro code-editor <= 1.0.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1827 affects the Flask Micro plugin for WordPress (up to version 1.0.0) with a CVSS score of 6.4. Authenticated users can exploit this XSS vulnerability, so patching is crucial to prevent script injection.
March 18, 2026
CVE-2026-1215: MMA Call Tracking <= 2.3.15 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule
CVE-2026-1215 affects the MMA Call Tracking plugin for WordPress (up to version 2.3.15) with a medium severity CVSS score of 4.3. Ensure to patch to prevent unauthorized configuration changes via CSRF attacks.
March 18, 2026
CVE-2026-0724: WPlyr Media Block <= 1.3.0 Authenticated (Administrator+) Stored Cross-Site Scripting via '_wplyr_accent_color' Parameter PoC, Patch Analysis & Rule
CVE-2026-0724 affects the WPlyr Media Block plugin (up to v1.3.0) with a CVSS score of 4.4. Authenticated attackers can exploit stored XSS vulnerabilities. Patching is recommended to mitigate risks.
March 18, 2026
CVE-2025-15440: iONE360 configurator <= 2.0.57 Unauthenticated Stored Cross-Site Scripting via Contact Form Parameters PoC, Patch Analysis & Rule
CVE-2025-15440 affects the Ione360 Configurator plugin for WordPress (up to version 2.0.57) with a CVSS score of 7.2. Unauthenticated stored XSS can be exploited via contact form parameters; patching is essential.
March 18, 2026
CVE-2026-1885: Slideshow Wp <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'sswp-slide' Shortcode 'sswpid' Attribute PoC, Patch Analysis & Rule
CVE-2026-1885 affects the Slideshow Wp plugin (up to version 1.1) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability, so ensure you update to the patched version.
March 18, 2026
CVE-2026-1809: HTML Shortcodes <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
CVE-2026-1809 affects the Html Shortcodes plugin for WordPress, with a CVSS score of 6.4. Users should update to the patched version to mitigate the risk of stored XSS attacks from authenticated users.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
