Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

2026-02-27

CVE-2026-28101: UberSlider MouseInteraction <= 2.3 – Reflected Cross-Site Scripting (uberSlider_mouseinteraction)

The UberSlider MouseInteraction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such…
2026-02-27

CVE-2026-28099: UberSlider Ultra <= 2.3 – Reflected Cross-Site Scripting (uberSlider_ultra)

The UberSlider Ultra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such…
2026-02-27

CVE-2026-28100: UberSlider PerpetuumMobile <= 2.3 – Reflected Cross-Site Scripting (uberSlider_perpetuummobile)

The UberSlider PerpetuumMobile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such…
2026-02-27

CVE-2026-28102: UberSlider Classic <= 2.5 – Reflected Cross-Site Scripting (uberSlider_classic)

The UberSlider Classic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such…
2026-02-27

CVE-2026-2471: WP Mail Logging <= 1.15.0 – Unauthenticated PHP Object Injection via Email Log Message Field (wp-mail-logging)

The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of untrusted input from the email log message field. This is due to the `BaseModel` class constructor calling `maybe_unserialize()` on all properties retrieved from the database without validation. This makes it possible…
2026-02-27

CVE-2025-13673: Tutor LMS <= 3.9.6 – Unauthenticated SQL Injection via coupon_code (tutor)

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 3.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers…
2026-02-26

CVE-2026-1565: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 – Authenticated (Author+) Arbitrary File Upload (wp-user-frontend)

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' function in all versions up to, and including, 4.2.8. This makes it possible for authenticated attackers, with Author-level…
2026-02-26

CVE-2026-28126: RH Frontend Publishing Pro <= 4.3.2 – Reflected Cross-Site Scripting (rh-frontend)

The RH Frontend Publishing Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an…
2026-02-26

CVE-2026-28114: WooCommerce License Manager <= 7.0.6 – Authenticated (Shop Manager+) Arbitrary File Upload (fs-license-manager)

The WooCommerce License Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 7.0.6. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution…
2026-02-26

CVE-2026-28103: Responsive Zoom In/Out Slider WordPress Plugin <= 5.4.5 – Reflected Cross-Site Scripting (lbg_zoominoutslider)

The Responsive Zoom In/Out Slider WordPress Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into…

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works