Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-0910: wpForo Forum <= 2.4.13 Authenticated (Subscriber+) PHP Object Injection PoC, Patch Analysis & Rule

CVE-2026-0910 affects the wpForo plugin (up to v2.4.13) with a high severity CVSS score of 8.8. Authenticated users can exploit a PHP Object Injection vulnerability, requiring patching to v2.4.14 for mitigation.
March 18, 2026

CVE-2025-14541: Lucky Wheel Giveaway <= 1.0.22 Authenticated (Administrator+) Remote Code Execution via 'conditional_tags' Parameter PoC, Patch Analysis & Rule

CVE-2025-14541 affects the Wp Lucky Wheel plugin (up to 1.0.22) with a CVSS score of 7.2. Authenticated attackers can exploit this high-severity remote code execution vulnerability. Patching is essential to mitigate risks.
March 18, 2026

CVE-2025-13391: Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) <= 4.9.60 Missing Authorization to Unauthenticated Arbitrary Attachment and Dropbox File Deletion PoC, Patch Analysis & Rule

CVE-2025-13391 affects the Uni Woo Custom Product Options Premium plugin (up to version 4.9.60) with a CVSS score of 5.8. Unauthenticated attackers can delete files, so patching is essential to mitigate this risk.
March 18, 2026

CVE-2026-25423: Real 3D FlipBook <= 4.19.1 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-25423 affects the Real3D Flipbook Lite plugin (up to version 4.19.1) with a medium severity (CVSS 4.3) vulnerability. Ensure you update to version 4.19.2 to mitigate unauthorized access risks.
March 18, 2026

CVE-2025-68552: WooCommerce Coming Soon Product with Countdown <= 5.0 Authenticated (Subscriber+) Local File Inclusion PoC, Patch Analysis & Rule

CVE-2025-68552 affects the Woo Coming Soon Product plugin for WordPress (up to version 5.0) with a CVSS score of 7.5. Authenticated attackers can exploit this high-severity vulnerability to execute arbitrary PHP code, making patching...
March 18, 2026

CVE-2025-67998: Miraculous Elementor <= 2.0.7 Authenticated (Subscriber+) Privilege Escalation PoC, Patch Analysis & Rule

CVE-2025-67998 affects the Miraculous Elementor plugin for WordPress (up to version 2.0.7) with a CVSS score of 8.8. Authenticated users can escalate privileges, emphasizing the need for immediate patching.
March 18, 2026

CVE-2025-69390: Business Template Blocks for WPBakery (Visual Composer) Page Builder <= 1.3.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-69390 affects the Templates And Addons For WPBakery Page Builder plugin (v1.3.2) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Users should update to the patched version to mitigate potential attacks.
March 18, 2026

CVE-2025-69389: Visitor Maps Extended Referer Field <= 1.2.6 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-69389 affects the Visitor Maps Extended Referer Field plugin for WordPress, with a medium severity CVSS score of 6.1. Users should upgrade to version 2.2.3 to mitigate the reflected cross-site scripting vulnerability.
March 18, 2026

CVE-2026-1866: Name Directory <= 1.32.0 Unauthenticated Stored Cross-Site Scripting via Double HTML-Entity Encoding in Submission Form PoC, Patch Analysis & Rule

CVE-2026-1866 affects the Name Directory plugin for WordPress (up to 1.32.0) with a high severity CVSS score of 7.2. Patch to version 1.32.1 to mitigate the stored XSS risk from user submissions.
March 18, 2026

CVE-2026-2268: Ninja Forms <= 3.14.0 Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action PoC, Patch Analysis & Rule

CVE-2026-2268 affects Ninja Forms plugin versions up to 3.14.0, allowing unauthenticated attackers to access sensitive post metadata. Upgrade to version 3.14.1 to mitigate this high-severity vulnerability.
March 18, 2026

CVE-2026-1922: The Events Calendar Shortcode & Block <= 3.1.2 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2026-1922 affects The Events Calendar Shortcode plugin (up to v3.1.2) with a medium severity (CVSS 6.4) XSS vulnerability. Update to v3.1.3 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026

CVE-2025-14895: PopupKit <= 2.2.0 Missing Authorization to Sensitive Information Disclosure and Data Deletion PoC, Patch Analysis & Rule

CVE-2025-14895 affects Popup Builder Block plugin versions up to 2.2.0, with a medium severity (CVSS 5.4) authentication bypass vulnerability. Update to 2.2.1 to secure sensitive analytics data from unauthorized access.
March 18, 2026

CVE-2026-1722: WCFM Marketplace <= 3.7.0 Insecure Direct Object Reference to Unauthenticated Arbitrary Refund Request Creation PoC, Patch Analysis & Rule

CVE-2026-1722 affects the Wc Multivendor Marketplace plugin (up to v3.7.0), exposing it to remote code execution. Update to v3.7.1 to mitigate unauthorized refund requests and prevent potential financial loss.
March 18, 2026

CVE-2025-69328: Booking and Rental Manager <= 2.5.9 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule

CVE-2025-69328 affects the Booking And Rental Manager For Woocommerce plugin (v2.5.9) with a CVSS score of 7.5. Authenticated attackers can exploit a file upload vulnerability, so ensure you update to the patched version.
March 18, 2026

CVE-2025-15147: WCFM Membership – WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 Insecure Direct Object Reference to Update Membership Payment PoC, Patch Analysis & Rule

CVE-2025-15147 affects the Wc Multivendor Membership plugin (up to 2.11.8) with a CVSS score of 4.3. Authenticated attackers can exploit it to alter membership payments. Upgrade to version 2.11.9 to mitigate this risk.
March 18, 2026

CVE-2026-0845: WCFM WooCommerce Frontend Manager <= 6.7.24 Authenticated (Shop Manager+) Arbitrary Options Update PoC, Patch Analysis & Rule

CVE-2026-0845 affects the Wc Frontend Manager plugin (up to 6.7.24) with a CVSS score of 7.2. This high-severity vulnerability allows authenticated attackers to modify site options. Users should update to version 6.7.25 to mitigate risks.
March 18, 2026

CVE-2025-69326: NEX-Forms <= 9.1.7 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2025-69326 affects the Nex Forms Express WP Form Builder plugin (up to v9.1.7) with a medium severity CVSS score of 6.1. Patch to v9.1.8 to mitigate reflected XSS risks from unauthenticated attackers.
March 18, 2026

CVE-2025-67994: YayCurrency <= 3.3 Missing Authorization to Unauthenticated Arbitrary Post Deletion PoC, Patch Analysis & Rule

CVE-2025-67994 affects the Yaycurrency plugin (up to v3.3) with a medium severity (CVSS 5.3) vulnerability allowing remote code execution. Update to v3.3.1 to mitigate unauthorized data modification risks.
March 18, 2026

CVE-2025-69388: Cliengo – Chatbot <= 3.0.4 Missing Authorization PoC, Patch Analysis & Rule

CVE-2025-69388 affects the Cliengo plugin (up to v3.0.4) with a CVSS score of 4.3. It allows authenticated users to perform unauthorized actions. Update to v3.0.5 to mitigate this risk.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works