
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1826: OpenPOS Lite <= 3.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
CVE-2026-1826 affects OpenPOS Lite Version 3.0, allowing authenticated attackers to exploit a stored XSS vulnerability with a CVSS score of 6.4. Upgrade to version 3.1 to mitigate this risk.
March 18, 2026
CVE-2026-28114: WooCommerce License Manager <= 7.0.6 Authenticated (Shop Manager+) Arbitrary File Upload PoC, Patch Analysis & Rule
CVE-2026-28114 affects the Fs License Manager plugin for WordPress (up to v7.0.6) with a high severity CVSS score of 7.2. Authenticated attackers can exploit this file upload vulnerability, risking remote code execution. Patching is...
March 18, 2026
CVE-2026-28126: RH Frontend Publishing Pro <= 4.3.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-28126 affects the RH Frontend Publishing Pro plugin (up to version 4.3.2) with a medium severity CVSS score of 6.1. Ensure to patch to avoid cross-site scripting risks from unauthenticated attackers.
March 18, 2026
CVE-2026-1311: Worry Proof Backup <= 0.2.4 Authenticated (Subscriber+) Path Traversal via Backup Upload PoC, Patch Analysis & Rule
CVE-2026-1311 affects the Worry Proof Backup plugin for WordPress (up to 0.2.4) with a CVSS score of 8.8. Authenticated attackers can exploit a path traversal vulnerability to execute arbitrary code. Update to the patched version.
March 18, 2026
CVE-2026-2356: User Registration & Membership <= 5.1.2 Insecure Direct Object Reference to Unauthenticated Limited User Deletion PoC, Patch Analysis & Rule
CVE-2026-2356 affects the User Registration plugin (up to v5.1.2) with a CVSS score of 5.3. Unauthenticated attackers can delete newly registered user accounts. Upgrade to v5.1.3 to mitigate this risk.
March 18, 2026
CVE-2026-1565: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 Authenticated (Author+) Arbitrary File Upload PoC, Patch Analysis & Rule
CVE-2026-1565 affects the Wp User Frontend plugin (up to v4.2.8) with a high severity CVSS score of 8.8. Patch to v4.2.9 to mitigate arbitrary file upload risks that could lead to remote code execution.
March 18, 2026
CVE-2026-1779: User Registration & Membership <= 5.1.2 Authentication Bypass PoC, Patch Analysis & Rule
CVE-2026-1779 affects the User Registration plugin for WordPress (up to version 5.1.2) with a high severity (CVSS 8.1) authentication bypass vulnerability. Upgrade to version 5.1.3 to mitigate this risk.
March 18, 2026
CVE-2026-2489: TP2WP Importer <= 1.1 Authenticated (Administrator+) Stored Cross-Site Scripting via 'Watched domains' Textarea PoC, Patch Analysis & Rule
CVE-2026-2489 affects the Tp2wp Importer plugin (v1.1) with a medium severity CVSS score of 4.4. Authenticated attackers can exploit stored XSS via the 'Watched domains' field. Update to the patched version to mitigate this risk.
March 18, 2026
CVE-2026-1557: WP Responsive Images <= 1.0 Unauthenticated Path Traversal to Arbitrary File Read via src PoC, Patch Analysis & Rule
CVE-2026-1557 affects the WP Responsive Images plugin (v1.0) with a high severity CVSS score of 7.5. This path traversal vulnerability allows unauthenticated attackers to read sensitive files. Update to the patched version to mitigate...
March 18, 2026
CVE-2026-2029: Livemesh Addons for Beaver Builder <= 3.9.2 Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' and 'value' Shortcode Attributes PoC, Patch Analysis & Rule
CVE-2026-2029 affects the Addons For Beaver Builder plugin (up to v3.9.2) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit stored XSS vulnerabilities, making timely patching essential.
March 18, 2026
CVE-2026-2498: WP Social Meta <= 1.0.1 Authenticated (Administrator+) Stored Cross-Site Scripting via Settings PoC, Patch Analysis & Rule
CVE-2026-2498 affects WP Social Meta plugin versions up to 1.0.1 with a CVSS score of 4.4. Admin-level users can exploit stored XSS vulnerabilities, impacting multi-site installations. Patching is essential for security.
March 18, 2026
CVE-2026-1833: WaMate Confirm <= 2.0.1 Missing Authorization to Authenticated (Subscriber+) Arbitrary Phone Number Blocking/Unblocking PoC, Patch Analysis & Rule
CVE-2026-1833 affects the WaMate Confirm plugin for WordPress (up to 2.0.1) with a medium severity (CVSS 5.3). Authenticated users can block/unblock phone numbers, a function meant for admins. Patching is essential.
March 18, 2026
CVE-2026-1786: Twitter posts to Blog <= 1.11.25 Missing Authorization to Unauthenticated Plugin Settings Update PoC, Patch Analysis & Rule
CVE-2026-1786 affects the Twitter Posts To Blog plugin (up to version 1.11.25) with a medium severity (CVSS 6.5) vulnerability allowing unauthorized data modification. Update to the patched version to mitigate risks.
March 18, 2026
CVE-2026-0815: Category Image <= 2.0 Authenticated (Editor+) Stored Cross-Site Scripting via 'tag-image' Parameter PoC, Patch Analysis & Rule
CVE-2026-0815 affects the Category Image plugin for WordPress (up to v2.0) with a medium severity CVSS of 4.4. Authenticated attackers can exploit stored XSS via the 'tag-image' parameter. Patch immediately to mitigate risks.
March 18, 2026
CVE-2026-1821: Microtango <= 0.9.29 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
CVE-2026-1821 affects the Microtango plugin (up to v0.9.29) with a medium severity (CVSS 6.4) XSS vulnerability. Update to v0.9.30 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026
CVE-2026-1357: Migration, Backup, Staging <= 0.9.123 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule
CVE-2026-1357 affects WPvivid Backup & Migration plugin versions up to 0.9.123, allowing unauthenticated file uploads with a CVSS score of 9.8. Update to 0.9.124 to mitigate remote code execution risks.
March 18, 2026
CVE-2025-15524: Gallery by FooGallery <= 3.1.9 Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Metadata Exposure PoC, Patch Analysis & Rule
CVE-2025-15524 affects the FooGallery plugin (up to version 3.1.9) with a medium severity (CVSS 4.3) vulnerability. Authenticated users can access private gallery metadata. Update to the patched version to mitigate this risk.
March 18, 2026
CVE-2025-13431: SlimStat Analytics <= 5.3.1 Authenticated (Subscriber+) SQL Injection via `args` Parameter PoC, Patch Analysis & Rule
CVE-2025-13431 affects the SlimStat Analytics plugin for WordPress, versions 5.3.1 and earlier, with a medium severity CVSS score of 6.5. Patch to version 5.3.2 to mitigate SQL injection risks for authenticated users.
March 18, 2026
CVE-2026-1231: Beaver Builder Page Builder – Drag and Drop Website Builder <= 2.10.0.5 Authenticated (Custom+) Missing Authorization to Stored Cross-Site Scripting via Global Settings PoC, Patch Analysis & Rule
CVE-2026-1231 affects Beaver Builder Lite up to version 2.10.0.5 with a CVSS score of 6.4. This medium-severity XSS vulnerability allows authenticated attackers to inject scripts, impacting user security. Update to the latest version to...
March 18, 2026
CVE-2026-1893: Orbisius Random Name Generator <= 1.0.2 Authenticated (Contributor+) Stored Cross-Site Scripting via 'btn_label' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1893 affects the Orbisius Random Name Generator plugin (up to 1.0.2) with a medium severity CVSS score of 6.4. Authenticated users can exploit this XSS vulnerability, so update to version 1.0.3 to mitigate risks.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
