
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-0910: wpForo Forum <= 2.4.13 Authenticated (Subscriber+) PHP Object Injection PoC, Patch Analysis & Rule
CVE-2026-0910 affects the wpForo plugin (up to v2.4.13) with a high severity CVSS score of 8.8. Authenticated users can exploit a PHP Object Injection vulnerability, requiring patching to v2.4.14 for mitigation.
March 18, 2026
CVE-2025-14541: Lucky Wheel Giveaway <= 1.0.22 Authenticated (Administrator+) Remote Code Execution via 'conditional_tags' Parameter PoC, Patch Analysis & Rule
CVE-2025-14541 affects the Wp Lucky Wheel plugin (up to 1.0.22) with a CVSS score of 7.2. Authenticated attackers can exploit this high-severity remote code execution vulnerability. Patching is essential to mitigate risks.
March 18, 2026
CVE-2025-13391: Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) <= 4.9.60 Missing Authorization to Unauthenticated Arbitrary Attachment and Dropbox File Deletion PoC, Patch Analysis & Rule
CVE-2025-13391 affects the Uni Woo Custom Product Options Premium plugin (up to version 4.9.60) with a CVSS score of 5.8. Unauthenticated attackers can delete files, so patching is essential to mitigate this risk.
March 18, 2026
CVE-2026-25423: Real 3D FlipBook <= 4.19.1 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-25423 affects the Real3D Flipbook Lite plugin (up to version 4.19.1) with a medium severity (CVSS 4.3) vulnerability. Ensure you update to version 4.19.2 to mitigate unauthorized access risks.
March 18, 2026
CVE-2025-68552: WooCommerce Coming Soon Product with Countdown <= 5.0 Authenticated (Subscriber+) Local File Inclusion PoC, Patch Analysis & Rule
CVE-2025-68552 affects the Woo Coming Soon Product plugin for WordPress (up to version 5.0) with a CVSS score of 7.5. Authenticated attackers can exploit this high-severity vulnerability to execute arbitrary PHP code, making patching...
March 18, 2026
CVE-2025-67998: Miraculous Elementor <= 2.0.7 Authenticated (Subscriber+) Privilege Escalation PoC, Patch Analysis & Rule
CVE-2025-67998 affects the Miraculous Elementor plugin for WordPress (up to version 2.0.7) with a CVSS score of 8.8. Authenticated users can escalate privileges, emphasizing the need for immediate patching.
March 18, 2026
CVE-2025-69390: Business Template Blocks for WPBakery (Visual Composer) Page Builder <= 1.3.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-69390 affects the Templates And Addons For WPBakery Page Builder plugin (v1.3.2) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Users should update to the patched version to mitigate potential attacks.
March 18, 2026
CVE-2025-69389: Visitor Maps Extended Referer Field <= 1.2.6 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-69389 affects the Visitor Maps Extended Referer Field plugin for WordPress, with a medium severity CVSS score of 6.1. Users should upgrade to version 2.2.3 to mitigate the reflected cross-site scripting vulnerability.
March 18, 2026
CVE-2026-1560: Custom Block Builder – Lazy Blocks <= 4.2.0 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule
CVE-2026-1560 affects the Lazy Blocks plugin (
March 18, 2026
CVE-2026-1866: Name Directory <= 1.32.0 Unauthenticated Stored Cross-Site Scripting via Double HTML-Entity Encoding in Submission Form PoC, Patch Analysis & Rule
CVE-2026-1866 affects the Name Directory plugin for WordPress (up to 1.32.0) with a high severity CVSS score of 7.2. Patch to version 1.32.1 to mitigate the stored XSS risk from user submissions.
March 18, 2026
CVE-2026-2268: Ninja Forms <= 3.14.0 Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action PoC, Patch Analysis & Rule
CVE-2026-2268 affects Ninja Forms plugin versions up to 3.14.0, allowing unauthenticated attackers to access sensitive post metadata. Upgrade to version 3.14.1 to mitigate this high-severity vulnerability.
March 18, 2026
CVE-2026-1922: The Events Calendar Shortcode & Block <= 3.1.2 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
CVE-2026-1922 affects The Events Calendar Shortcode plugin (up to v3.1.2) with a medium severity (CVSS 6.4) XSS vulnerability. Update to v3.1.3 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026
CVE-2025-14895: PopupKit <= 2.2.0 Missing Authorization to Sensitive Information Disclosure and Data Deletion PoC, Patch Analysis & Rule
CVE-2025-14895 affects Popup Builder Block plugin versions up to 2.2.0, with a medium severity (CVSS 5.4) authentication bypass vulnerability. Update to 2.2.1 to secure sensitive analytics data from unauthorized access.
March 18, 2026
CVE-2026-1722: WCFM Marketplace <= 3.7.0 Insecure Direct Object Reference to Unauthenticated Arbitrary Refund Request Creation PoC, Patch Analysis & Rule
CVE-2026-1722 affects the Wc Multivendor Marketplace plugin (up to v3.7.0), exposing it to remote code execution. Update to v3.7.1 to mitigate unauthorized refund requests and prevent potential financial loss.
March 18, 2026
CVE-2025-69328: Booking and Rental Manager <= 2.5.9 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
CVE-2025-69328 affects the Booking And Rental Manager For Woocommerce plugin (v2.5.9) with a CVSS score of 7.5. Authenticated attackers can exploit a file upload vulnerability, so ensure you update to the patched version.
March 18, 2026
CVE-2025-15147: WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 Insecure Direct Object Reference to Update Membership Payment PoC, Patch Analysis & Rule
CVE-2025-15147 affects the Wc Multivendor Membership plugin (up to 2.11.8) with a CVSS score of 4.3. Authenticated attackers can exploit it to alter membership payments. Upgrade to version 2.11.9 to mitigate this risk.
March 18, 2026
CVE-2026-0845: WCFM WooCommerce Frontend Manager <= 6.7.24 Authenticated (Shop Manager+) Arbitrary Options Update PoC, Patch Analysis & Rule
CVE-2026-0845 affects the Wc Frontend Manager plugin (up to 6.7.24) with a CVSS score of 7.2. This high-severity vulnerability allows authenticated attackers to modify site options. Users should update to version 6.7.25 to mitigate risks.
March 18, 2026
CVE-2025-69326: NEX-Forms <= 9.1.7 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-69326 affects the Nex Forms Express WP Form Builder plugin (up to v9.1.7) with a medium severity CVSS score of 6.1. Patch to v9.1.8 to mitigate reflected XSS risks from unauthenticated attackers.
March 18, 2026
CVE-2025-67994: YayCurrency <= 3.3 Missing Authorization to Unauthenticated Arbitrary Post Deletion PoC, Patch Analysis & Rule
CVE-2025-67994 affects the Yaycurrency plugin (up to v3.3) with a medium severity (CVSS 5.3) vulnerability allowing remote code execution. Update to v3.3.1 to mitigate unauthorized data modification risks.
March 18, 2026
CVE-2025-69388: Cliengo – Chatbot <= 3.0.4 Missing Authorization PoC, Patch Analysis & Rule
CVE-2025-69388 affects the Cliengo plugin (up to v3.0.4) with a CVSS score of 4.3. It allows authenticated users to perform unauthorized actions. Update to v3.0.5 to mitigate this risk.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
