Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

June 26, 2026

CVE-2026-11356: Ivory Search <= 5.5.15 Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings PoC, Patch Analysis & Rule

CVE-2026-11356 affects the Ivory Search plugin for WordPress (up to version 5.5.15) with a medium severity (CVSS 4.4) stored XSS vulnerability. Update to version 5.5.16 to mitigate the risk of script injection by authenticated users.
June 26, 2026

CVE-2026-3462: Frisbii Pay <= 1.8.9 Missing Authorization to Authenticated (Subscriber+) Payment Token Modification PoC, Patch Analysis & Rule

CVE-2026-3462 affects the Reepay Checkout Gateway plugin (up to version 1.8.9) with a CVSS score of 6.5. Authenticated attackers can exploit this medium-severity vulnerability to modify WooCommerce data. Update to version 1.8.10.
June 26, 2026

CVE-2026-54188: JetEngine <= 3.8.10 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-54188 affects the Jet Engine plugin for WordPress (up to version 3.8.10) with a high severity CVSS score of 7.2. Unauthenticated attackers can exploit this stored XSS vulnerability, so patching is essential.
June 26, 2026

CVE-2025-13407: Gravity Forms <= 2.9.23.0 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule

CVE-2025-13407 affects the Gravity Forms plugin for WordPress (up to 2.9.23.0) with a CVSS score of 9.8. It allows unauthenticated file uploads, risking remote code execution. Update to the patched version to mitigate this critical...
June 25, 2026

CVE-2026-1869: User Registration & Membership <= 5.2.0 Missing Authorization to Unauthenticated Payment Bypass PoC, Patch Analysis & Rule

CVE-2026-1869 affects the User Registration plugin (up to version 5.2.0), allowing unauthenticated users to bypass payment processing. Update to version 5.2.1 to mitigate this medium severity vulnerability.
June 25, 2026

CVE-2026-13226: Groundhogg <= 4.5.4 Authenticated (Custom+) SQL Injection via 'after' Parameter PoC, Patch Analysis & Rule

CVE-2026-13226 affects the Groundhogg plugin for WordPress (up to 4.5.4) with a medium severity SQL injection (CVSS 6.5). Patch to version 4.5.5 to mitigate risks of sensitive data exposure.
June 25, 2026

CVE-2026-3652: ARForms <= 7.1.3 Unauthenticated Stored Cross-Site Scripting via 'value' Parameter PoC, Patch Analysis & Rule

CVE-2026-3652 affects the ARForms plugin for WordPress (up to version 7.1.3) with a high severity CVSS score of 7.2. Unauthenticated attackers can exploit stored XSS, impacting admin views. Patching is essential.
June 25, 2026

CVE-2026-10091: Email JavaScript Cloak <= 1.03 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-10091 affects the Email Javascript Cloaker plugin (v1.03) with a CVSS score of 7.2. It allows stored XSS via unsanitized shortcode attributes. Update to the patched version to mitigate this vulnerability.
June 25, 2026

CVE-2026-10530: Pie Register – User Registration, Profiles & Content Restriction < 3.8.4.10 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-10530 affects the Pie Register plugin for WordPress, allowing unauthorized access due to a missing capability check. Users should update to version 3.8.4.10 to mitigate this medium severity vulnerability (CVSS 5.3).
June 25, 2026

CVE-2026-12242: AdRotate Banner Manager <= 5.17.7 Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-12242 affects the AdRotate plugin (up to v5.17.7) with a CVSS score of 8.8. This high-severity PHP code injection vulnerability allows authenticated attackers to execute arbitrary code. Update to v5.17.8 to mitigate risks.
June 25, 2026

CVE-2026-11614: Xpro Addons <= 1.7.2 Authenticated (Author+) Stored Cross-Site Scripting via 'custom_attributes' Parameter of Multiple Widgets PoC, Patch Analysis & Rule

CVE-2026-11614 affects the Xpro Elementor Addons plugin (up to v1.7.2) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit this stored XSS vulnerability, so ensure you patch to the latest version.
June 25, 2026

CVE-2026-56011: MapPress Maps for WordPress <= 2.97.3 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-56011 affects MapPress Google Maps for WordPress versions up to 2.97.3, with a CVSS score of 7.2. Users should upgrade to version 2.97.4 to mitigate the high-severity stored cross-site scripting vulnerability.
June 25, 2026

CVE-2026-56014: Master Slider – Responsive Touch Slider <= 3.11.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-56014 affects the Master Slider plugin for WordPress (up to version 3.11.2) with a CVSS score of 7.2. Unauthenticated attackers can exploit this high-severity stored XSS vulnerability, making prompt patching essential.
June 25, 2026

CVE-2026-56013: License Manager for WooCommerce <= 3.0.15 Unauthenticated Insecure Direct Object Reference PoC, Patch Analysis & Rule

CVE-2026-56013 affects the License Manager for WooCommerce plugin (up to v3.0.15) with a CVSS score of 5.3. Unauthenticated attackers can exploit this medium-severity IDOR vulnerability. Update to v3.0.16 to mitigate risks.
June 25, 2026

CVE-2026-7859: Motors – Car Dealership & Classified Listings Plugin < 1.4.110 Cross-Site Request Forgery PoC, Patch Analysis & Rule

CVE-2026-7859 affects the Motors Car Dealership Classified Listings plugin for WordPress, with a medium severity CVSS score of 4.3. Ensure you update to version 1.4.110 to mitigate the cross-site request forgery risk.
June 25, 2026

CVE-2026-56005: WP Activity Log <= 5.6.3.1 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-56005 affects the WP Security Audit Log plugin (up to version 5.6.3.1) with a medium severity CVSS score of 6.4. Authenticated users can exploit stored XSS; update to 5.6.4 to mitigate risks.
June 25, 2026

CVE-2026-9822: WP Hotel Booking < 2.3.1 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-9822 affects the WP Hotel Booking plugin (up to version 2.3.1) with a medium severity score of 4.3. Ensure you update to the patched version to prevent unauthorized access by authenticated users.
June 25, 2026

CVE-2026-6858: Transbank Webpay < 1.14.0 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-6858 affects the Transbank Webpay Plus Rest plugin (up to version 1.14.0) with a CVSS score of 7.2. This high-severity Stored XSS vulnerability allows unauthenticated attackers to inject scripts. Update to the patched version...
June 25, 2026

CVE-2026-56025: Paymob for WooCommerce <= 4.1.2 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-56025 affects the Paymob for WooCommerce plugin (up to version 4.1.2) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability; ensure you update to the patched version.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works