
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
June 26, 2026
CVE-2026-11356: Ivory Search <= 5.5.15 Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings PoC, Patch Analysis & Rule
CVE-2026-11356 affects the Ivory Search plugin for WordPress (up to version 5.5.15) with a medium severity (CVSS 4.4) stored XSS vulnerability. Update to version 5.5.16 to mitigate the risk of script injection by authenticated users.
June 26, 2026
CVE-2026-3462: Frisbii Pay <= 1.8.9 Missing Authorization to Authenticated (Subscriber+) Payment Token Modification PoC, Patch Analysis & Rule
CVE-2026-3462 affects the Reepay Checkout Gateway plugin (up to version 1.8.9) with a CVSS score of 6.5. Authenticated attackers can exploit this medium-severity vulnerability to modify WooCommerce data. Update to version 1.8.10.
June 26, 2026
CVE-2026-54188: JetEngine <= 3.8.10 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-54188 affects the Jet Engine plugin for WordPress (up to version 3.8.10) with a high severity CVSS score of 7.2. Unauthenticated attackers can exploit this stored XSS vulnerability, so patching is essential.
June 26, 2026
CVE-2025-13407: Gravity Forms <= 2.9.23.0 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule
CVE-2025-13407 affects the Gravity Forms plugin for WordPress (up to 2.9.23.0) with a CVSS score of 9.8. It allows unauthenticated file uploads, risking remote code execution. Update to the patched version to mitigate this critical...
June 25, 2026
CVE-2026-1869: User Registration & Membership <= 5.2.0 Missing Authorization to Unauthenticated Payment Bypass PoC, Patch Analysis & Rule
CVE-2026-1869 affects the User Registration plugin (up to version 5.2.0), allowing unauthenticated users to bypass payment processing. Update to version 5.2.1 to mitigate this medium severity vulnerability.
June 25, 2026
CVE-2026-13226: Groundhogg <= 4.5.4 Authenticated (Custom+) SQL Injection via 'after' Parameter PoC, Patch Analysis & Rule
CVE-2026-13226 affects the Groundhogg plugin for WordPress (up to 4.5.4) with a medium severity SQL injection (CVSS 6.5). Patch to version 4.5.5 to mitigate risks of sensitive data exposure.
June 25, 2026
CVE-2026-7761: Ultimate Member <= 2.11.4 Authenticated (Contributor+) Account Takeover via Password Reset Link Disclosure PoC, Patch Analysis & Rule
CVE-2026-7761 affects the Ultimate Member plugin (versions
June 25, 2026
CVE-2026-3652: ARForms <= 7.1.3 Unauthenticated Stored Cross-Site Scripting via 'value' Parameter PoC, Patch Analysis & Rule
CVE-2026-3652 affects the ARForms plugin for WordPress (up to version 7.1.3) with a high severity CVSS score of 7.2. Unauthenticated attackers can exploit stored XSS, impacting admin views. Patching is essential.
June 25, 2026
CVE-2026-10091: Email JavaScript Cloak <= 1.03 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-10091 affects the Email Javascript Cloaker plugin (v1.03) with a CVSS score of 7.2. It allows stored XSS via unsanitized shortcode attributes. Update to the patched version to mitigate this vulnerability.
June 25, 2026
CVE-2026-10530: Pie Register – User Registration, Profiles & Content Restriction < 3.8.4.10 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-10530 affects the Pie Register plugin for WordPress, allowing unauthorized access due to a missing capability check. Users should update to version 3.8.4.10 to mitigate this medium severity vulnerability (CVSS 5.3).
June 25, 2026
CVE-2026-12242: AdRotate Banner Manager <= 5.17.7 Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-12242 affects the AdRotate plugin (up to v5.17.7) with a CVSS score of 8.8. This high-severity PHP code injection vulnerability allows authenticated attackers to execute arbitrary code. Update to v5.17.8 to mitigate risks.
June 25, 2026
CVE-2026-11614: Xpro Addons <= 1.7.2 Authenticated (Author+) Stored Cross-Site Scripting via 'custom_attributes' Parameter of Multiple Widgets PoC, Patch Analysis & Rule
CVE-2026-11614 affects the Xpro Elementor Addons plugin (up to v1.7.2) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit this stored XSS vulnerability, so ensure you patch to the latest version.
June 25, 2026
CVE-2026-56011: MapPress Maps for WordPress <= 2.97.3 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-56011 affects MapPress Google Maps for WordPress versions up to 2.97.3, with a CVSS score of 7.2. Users should upgrade to version 2.97.4 to mitigate the high-severity stored cross-site scripting vulnerability.
June 25, 2026
CVE-2026-56014: Master Slider – Responsive Touch Slider <= 3.11.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-56014 affects the Master Slider plugin for WordPress (up to version 3.11.2) with a CVSS score of 7.2. Unauthenticated attackers can exploit this high-severity stored XSS vulnerability, making prompt patching essential.
June 25, 2026
CVE-2026-56013: License Manager for WooCommerce <= 3.0.15 Unauthenticated Insecure Direct Object Reference PoC, Patch Analysis & Rule
CVE-2026-56013 affects the License Manager for WooCommerce plugin (up to v3.0.15) with a CVSS score of 5.3. Unauthenticated attackers can exploit this medium-severity IDOR vulnerability. Update to v3.0.16 to mitigate risks.
June 25, 2026
CVE-2026-7859: Motors – Car Dealership & Classified Listings Plugin < 1.4.110 Cross-Site Request Forgery PoC, Patch Analysis & Rule
CVE-2026-7859 affects the Motors Car Dealership Classified Listings plugin for WordPress, with a medium severity CVSS score of 4.3. Ensure you update to version 1.4.110 to mitigate the cross-site request forgery risk.
June 25, 2026
CVE-2026-56005: WP Activity Log <= 5.6.3.1 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-56005 affects the WP Security Audit Log plugin (up to version 5.6.3.1) with a medium severity CVSS score of 6.4. Authenticated users can exploit stored XSS; update to 5.6.4 to mitigate risks.
June 25, 2026
CVE-2026-9822: WP Hotel Booking < 2.3.1 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-9822 affects the WP Hotel Booking plugin (up to version 2.3.1) with a medium severity score of 4.3. Ensure you update to the patched version to prevent unauthorized access by authenticated users.
June 25, 2026
CVE-2026-6858: Transbank Webpay < 1.14.0 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-6858 affects the Transbank Webpay Plus Rest plugin (up to version 1.14.0) with a CVSS score of 7.2. This high-severity Stored XSS vulnerability allows unauthenticated attackers to inject scripts. Update to the patched version...
June 25, 2026
CVE-2026-56025: Paymob for WooCommerce <= 4.1.2 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-56025 affects the Paymob for WooCommerce plugin (up to version 4.1.2) with a medium severity CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability; ensure you update to the patched version.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
