
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1463: Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 4.0.4 Authenticated (Author+) Local File Inclusion PoC, Patch Analysis & Rule
CVE-2026-1463 affects NextGEN Gallery plugin (up to v4.0.4) with a high severity CVSS score of 8.8. Authenticated attackers can exploit this authentication bypass vulnerability. Upgrade to v4.0.5 to mitigate risks.
March 18, 2026
CVE-2026-2991: KiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 Unauthenticated Authentication Bypass via Social Login Token PoC, Patch Analysis & Rule
CVE-2026-2991 affects Kivicare Clinic Management System (up to 4.1.2) with a critical CVSS score of 9.8. Unauthenticated attackers can bypass authentication and access sensitive patient data. Upgrade to 4.1.3 to mitigate this risk.
March 18, 2026
CVE-2026-2992: KiviCare <= 4.1.2 Missing Authorization to Unauthenticated Privilege Escalation via Setup Wizard PoC, Patch Analysis & Rule
CVE-2026-2992 affects the Kivicare Clinic Management System plugin (up to version 4.1.2) with a high severity CVSS score of 8.2. Patch to version 4.1.3 to mitigate unauthorized clinic creation and admin access.
March 18, 2026
CVE-2026-1870: Thim Kit for Elementor <= 1.3.7 Missing Authorization to Unauthenticated Private Course Disclosure PoC, Patch Analysis & Rule
CVE-2026-1870 affects the Thim Elementor Kit plugin (up to version 1.3.7) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access to private course content. Users should update to version 1.3.8 to mitigate this risk.
March 18, 2026
CVE-2026-1948: NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license PoC, Patch Analysis & Rule
CVE-2026-1948 affects the Nex Forms Express WP Form Builder plugin (up to version 9.1.9) with a medium severity (CVSS 4.3). Update to version 9.1.10 to mitigate unauthorized license deactivation by authenticated users.
March 18, 2026
CVE-2026-1883: Wicked Folders <= 4.1.0 Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion PoC, Patch Analysis & Rule
CVE-2026-1883 affects the Wicked Folders plugin (up to version 4.1.0) with a medium severity (CVSS 4.3) vulnerability allowing authenticated users to delete folders of others. Update to version 4.1.1 to mitigate this risk.
March 18, 2026
CVE-2026-1947: NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id PoC, Patch Analysis & Rule
CVE-2026-1947 affects the Nex Forms Express WP Form Builder plugin (up to v9.1.9) with a CVSS score of 7.5. Unauthenticated attackers can overwrite form entries. Upgrade to v9.1.10 to mitigate this high-severity vulnerability.
March 18, 2026
CVE-2026-4063: Social Icons Widget & Block <= 4.5.8 Missing Authorization to Authenticated (Subscriber+) Sharing Configuration Creation PoC, Patch Analysis & Rule
CVE-2026-4063 affects the Social Icons Widget By WPZOOM plugin (up to version 4.5.8) with a medium severity (CVSS 4.3). Update to 4.5.9 to prevent unauthorized data modification by users with Subscriber-level access.
March 18, 2026
CVE-2026-2233: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter PoC, Patch Analysis & Rule
CVE-2026-2233 affects the Wp User Frontend plugin (up to v4.2.8) with a CVSS score of 5.3. It allows unauthorized data modification. Update to v4.2.9 to mitigate risks.
March 18, 2026
CVE-2026-2373: Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 Missing Authorization to Unauthenticated Custom Post Type Contents Exposure PoC, Patch Analysis & Rule
CVE-2026-2373 affects the Royal Elementor Addons plugin (v1.7.1049) with a medium severity (CVSS 5.3) vulnerability allowing remote code execution. Users should update to v1.7.1050 to mitigate risks of information exposure.
March 18, 2026
CVE-2026-2257: GetGenie <= 4.3.2 Insecure Direct Object Reference to Authenticated (Author+) Stored Cross-Site Scripting via REST API PoC, Patch Analysis & Rule
CVE-2026-2257 affects the GetGenie plugin (up to version 4.3.2) with a medium severity (CVSS 6.4) cross-site scripting vulnerability. Users should update to version 4.3.3 to mitigate risks associated with this flaw.
March 18, 2026
CVE-2026-3986: Calculated Fields Form <= 5.4.5.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Form Settings PoC, Patch Analysis & Rule
CVE-2026-3986 affects the Calculated Fields Form plugin (v5.4.5.0) with a medium severity (CVSS 6.4) cross-site scripting vulnerability. Users should upgrade to v5.4.5.1 to mitigate risks from authenticated attacks.
March 18, 2026
CVE-2026-2879: GetGenie <= 4.3.2 Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Post Overwrite/Deletion PoC, Patch Analysis & Rule
CVE-2026-2879 affects the Getgenie plugin (up to version 4.3.2) with a medium severity (CVSS 5.4) vulnerability. Update to 4.3.3 to prevent unauthorized post overwrites by authenticated users.
March 18, 2026
CVE-2026-2888: Formidable Forms <= 6.28 Unauthenticated Payment Amount Manipulation via 'item_meta' Parameter PoC, Patch Analysis & Rule
CVE-2026-2888 affects the Formidable plugin (up to version 6.28) with a medium severity (CVSS 5.3) CSRF vulnerability. Update to version 6.29 to prevent unauthorized payment manipulation.
March 18, 2026
CVE-2026-2987: Simple Ajax Chat <= 20260217 Unauthenticated Stored Cross-Site Scripting via 'c' PoC, Patch Analysis & Rule
CVE-2026-2987 affects the Simple Ajax Chat plugin for WordPress, allowing stored cross-site scripting in versions up to 20260217. Users should upgrade to version 20260301 to mitigate this medium severity vulnerability.
March 18, 2026
CVE-2026-2890: Formidable Forms <= 6.28 Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse PoC, Patch Analysis & Rule
CVE-2026-2890 affects the Formidable Forms plugin (up to v6.28) with a high severity (CVSS 7.5) vulnerability allowing payment integrity bypass. Update to v6.29 to mitigate unauthorized payment completions.
March 18, 2026
CVE-2026-3045: Appointment Booking Calendar <= 1.6.9.29 Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint PoC, Patch Analysis & Rule
CVE-2026-3045 affects the Simply Schedule Appointments plugin (up to 1.6.9.29) with a CVSS score of 7.5. Unauthenticated users can access sensitive admin settings. Update to version 1.6.10.0 to mitigate this risk.
March 18, 2026
CVE-2026-1704: Appointment Booking Calendar <= 1.6.9.29 Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure PoC, Patch Analysis & Rule
CVE-2026-1704 affects the Simply Schedule Appointments plugin (up to 1.6.9.29) with a medium severity (CVSS 4.3). Authenticated users can access sensitive appointment data. Upgrade to 1.6.10.0 to mitigate this risk.
March 18, 2026
CVE-2026-3891: Pix for WooCommerce <= 1.5.0 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule
CVE-2026-3891 affects the Payment Gateway Pix for WooCommerce plugin (v1.5.0) with a critical CVSS score of 9.8. Unauthenticated file uploads can lead to remote code execution; update to v1.6.0 to mitigate.
March 18, 2026
CVE-2026-3657: My Sticky Bar <= 2.8.6 Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action PoC, Patch Analysis & Rule
CVE-2026-3657 affects the My Sticky Menu plugin (up to version 2.8.6) with a high severity SQL injection vulnerability (CVSS 7.5). Update to version 2.8.7 to mitigate potential data extraction risks.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
