
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-0996: Fluent Forms <= 6.1.14 Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module PoC, Patch Analysis & Rule
CVE-2026-0996 affects the Fluent Forms plugin (up to v6.1.14) with a CVSS score of 6.4. This medium-severity XSS vulnerability allows Subscriber-level users to inject scripts. Update to v6.1.15 to mitigate risks.
March 18, 2026
CVE-2026-24953: Simple File List <= 6.1.15 Authenticated (Subscriber+) Arbitrary File Download PoC, Patch Analysis & Rule
CVE-2026-24953 affects the Simple File List plugin (up to 6.1.15) with a medium severity (CVSS 6.5) path traversal vulnerability. Update to version 6.1.16 to mitigate risks of unauthorized file access.
March 18, 2026
CVE-2025-69384: Timeline Event History <= 3.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-69384 affects the Timeline Event History plugin for WordPress (up to version 3.2) with a medium severity CVSS score of 6.1. Users should patch to mitigate the risk of reflected cross-site scripting attacks.
March 18, 2026
CVE-2025-67991: User Extra Fields <= 16.8 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2025-67991 affects the Wp User Extra Fields plugin (up to version 16.8) with a high severity CVSS score of 7.2 due to stored cross-site scripting. Ensure you update to the patched version to mitigate risks.
March 18, 2026
CVE-2025-69387: Simple Retail Menus <= 4.2.1 Unauthenticated Local File Inclusion PoC, Patch Analysis & Rule
CVE-2025-69387 affects the Simple Retail Menus plugin (up to v4.2.1) with a high severity CVSS of 8.1. Unauthenticated attackers can exploit this authentication bypass for remote code execution. Update to the patched version immediately.
March 18, 2026
CVE-2025-67993: Atarim <= 4.2.1 Missing Authorization PoC, Patch Analysis & Rule
CVE-2025-67993 affects Atarim Visual Collaboration plugin versions up to 4.2.1, with a CVSS score of 5.3. Patch to version 4.2.2 to mitigate unauthorized access risks.
March 18, 2026
CVE-2026-24955: Whizz Plugins <= 1.9 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-24955 affects Whizz Plugins for WordPress (v1.9 and below) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Users should update to the patched version to mitigate potential script injection risks.
March 18, 2026
CVE-2025-69382: Themesflat Elementor <= 1.0.1 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
CVE-2025-69382 affects the Themesflat Elementor plugin (v1.0.1 and earlier) with a CVSS score of 8.1. This high-severity file upload vulnerability allows unauthenticated PHP object injection, requiring immediate patching.
March 18, 2026
CVE-2025-69383: shop <= 2.6.1 Unauthenticated Local File Inclusion PoC, Patch Analysis & Rule
CVE-2025-69383 affects the Wpshop plugin (up to 2.6.1) with a CVSS score of 8.1, allowing unauthenticated attackers to execute arbitrary PHP files. Users should update to the patched version to mitigate this high-severity vulnerability.
March 18, 2026
CVE-2025-69381: WooCommerce Bulk Product Editor <= 3.0 Missing Authorization PoC, Patch Analysis & Rule
CVE-2025-69381 affects the WooCommerce Quick Product Editor plugin (up to v3.0) with a medium severity (CVSS 4.3) remote code execution vulnerability. Ensure to update to the patched version to mitigate unauthorized access risks.
March 18, 2026
CVE-2025-69380: Upload Files Anywhere <= 2.8 Unauthenticated Arbitrary File Download PoC, Patch Analysis & Rule
CVE-2025-69380 affects the WordPress Upload Files Anywhere plugin (up to version 2.8) with a CVSS score of 7.5. Unauthenticated attackers can exploit this high-severity path traversal vulnerability to access sensitive server files.
March 18, 2026
CVE-2025-69379: Upload Files Anywhere <= 2.8 Unauthenticated Arbitrary File Deletion PoC, Patch Analysis & Rule
CVE-2025-69379 reveals a critical file upload vulnerability in the Wp Upload Files Anywhere plugin (up to v2.8) with a CVSS score of 9.1. Unauthenticated attackers can delete files, risking remote code execution. Update to the patched...
March 18, 2026
CVE-2025-69325: Primer MyData for Woocommerce <= 4.2.8 Unauthenticated Path Traversal PoC, Patch Analysis & Rule
CVE-2025-69325 affects the Primer MyData plugin for WordPress (versions
March 18, 2026
CVE-2026-3090: Post SMTP <= 3.8.0 Unauthenticated Stored Cross-Site Scripting via 'event_type' PoC, Patch Analysis & Rule
CVE-2026-3090 affects Post SMTP plugin versions up to 3.8.0 with a CVSS score of 7.2. It allows stored XSS attacks. Users should upgrade to version 3.9.0 to mitigate risks.
March 18, 2026
CVE-2026-1926: Subscriptions for WooCommerce <= 1.9.2 Missing Authorization to Unauthenticated Arbitrary Subscription Cancellation PoC, Patch Analysis & Rule
CVE-2026-1926 affects the Subscriptions For WooCommerce plugin (up to v1.9.2) with a CVSS score of 5.3. This medium severity remote code execution vulnerability allows unauthorized cancellation of subscriptions. Update to v1.9.3.
March 18, 2026
CVE-2026-3512: Writeprint Stylometry <= 0.1 Reflected Cross-Site Scripting via 'p' Parameter PoC, Patch Analysis & Rule
CVE-2026-3512 affects the Writeprint Stylometry plugin (v0.1) with a medium severity (CVSS 6.1) reflected XSS vulnerability. Ensure to patch or mitigate to prevent authenticated attackers from injecting scripts.
March 18, 2026
CVE-2026-4268: WP Go Maps (formerly WP Google Maps) <= 10.0.05 Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings PoC, Patch Analysis & Rule
CVE-2026-4268 affects WP Google Maps plugin versions up to 10.0.05, with a CVSS score of 6.4. Authenticated users can exploit this medium-severity XSS vulnerability, making timely patching essential for security.
March 18, 2026
CVE-2026-1217: Yoast Duplicate Post <= 4.5 Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite PoC, Patch Analysis & Rule
CVE-2026-1217 affects the Yoast Duplicate Post plugin (up to v4.5) with a medium severity (CVSS 5.4) vulnerability. Users should upgrade to v4.6 to prevent unauthorized post duplication and overwriting.
March 18, 2026
CVE-2026-1780: [CR]Paid Link Manager <= 0.5 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-1780 affects the Crpaid Link Manager plugin for WordPress, with a medium severity CVSS score of 6.1. Users should upgrade to version 0.6 to mitigate the reflected XSS vulnerability.
March 18, 2026
CVE-2026-2512: Code Embed <= 2.5.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields PoC, Patch Analysis & Rule
CVE-2026-2512 affects the Simple Embed Code plugin (up to v2.5.1) with a CVSS score of 6.4. This medium severity cross-site scripting vulnerability allows authenticated users to inject scripts. Upgrade to v2.5.2 to mitigate.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
