
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1708: Appointment Booking Calendar <= 1.6.9.27 Unauthenticated SQL Injection via 'append_where_sql' Parameter PoC, Patch Analysis & Rule
CVE-2026-1708 affects the Simply Schedule Appointments plugin (versions
March 18, 2026
CVE-2026-3231: Checkout Field Editor (Checkout Manager) for WooCommerce <= 2.1.7 Unauthenticated Stored Cross-Site Scripting via Block Checkout Custom Radio Field PoC, Patch Analysis & Rule
CVE-2026-3231 affects Woo Checkout Field Editor Pro (up to v2.1.7) with a high severity CVSS score of 7.2. Unauthenticated attackers can exploit a stored XSS vulnerability. Upgrade to v2.1.8 to mitigate risks.
March 18, 2026
CVE-2026-3492: Gravity Forms <= 2.9.28.1 Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title PoC, Patch Analysis & Rule
CVE-2026-3492 affects Gravity Forms versions up to 2.9.28.1, with a CVSS score of 6.4. It allows authenticated users to exploit stored XSS vulnerabilities. Update to the latest version to mitigate risks.
March 18, 2026
CVE-2026-1993: ExactMetrics 7.1.0 9.0.2 Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update PoC, Patch Analysis & Rule
CVE-2026-1993 affects the Google Analytics Dashboard for WP plugin (versions 7.1.0 to 9.0.2) with a CVSS score of 8.8. Update to version 9.0.3 to mitigate improper privilege management risks.
March 18, 2026
CVE-2026-3226: LearnPress <= 4.3.2.8 Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering PoC, Patch Analysis & Rule
CVE-2026-3226 affects the LearnPress plugin (up to v4.3.2.8) with a medium severity (CVSS 4.3). It allows authenticated users to trigger unauthorized email notifications. Update to v4.3.3 to mitigate this risk.
March 18, 2026
CVE-2026-2466: DukaPress <= 3.2.4 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-2466 affects the DukaPress plugin (up to version 3.2.4) with a high severity CVSS score of 7.2. Unauthenticated attackers can exploit this stored XSS vulnerability, making patching essential for user security.
March 18, 2026
CVE-2026-1992: ExactMetrics 8.6.0 9.0.2 Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation PoC, Patch Analysis & Rule
CVE-2026-1992 affects the Google Analytics Dashboard for WP plugin (versions 8.6.0 to 9.0.2) with a CVSS score of 8.8. Patch to version 9.0.3 to mitigate remote code execution risks from insecure direct object reference.
March 18, 2026
CVE-2026-2917: Happy Addons for Elementor <= 3.21.0 Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter PoC, Patch Analysis & Rule
CVE-2026-2917 affects the Happy Elementor Addons plugin (up to v3.21.0) with a medium severity (CVSS 5.4) vulnerability. Update to v3.21.1 to mitigate risks of unauthorized content cloning by authenticated users.
March 18, 2026
CVE-2026-3496: JetBooking <= 4.0.3 Unauthenticated SQL Injection via 'check_in_date' Parameter PoC, Patch Analysis & Rule
CVE-2026-3496 affects the Jet Booking plugin (up to version 4.0.3) with a high severity score of 7.5. This SQL injection vulnerability allows unauthenticated attackers to extract sensitive data. Ensure you update to the patched version.
March 18, 2026
CVE-2026-3222: WP Maps <= 4.9.1 Unauthenticated SQL Injection via 'location_id' Parameter PoC, Patch Analysis & Rule
CVE-2026-3222 affects the WP Google Map Plugin (up to v4.9.1) with a high severity CVSS of 7.5 due to SQL injection vulnerabilities. Upgrade to v4.9.2 to mitigate risks from unauthenticated attacks.
March 18, 2026
CVE-2026-2918: Happy Addons for Elementor <= 3.21.0 Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions PoC, Patch Analysis & Rule
CVE-2026-2918 affects Happy Elementor Addons plugin versions up to 3.21.0, with a CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability; update to version 3.21.1 to mitigate risks.
March 18, 2026
CVE-2026-2358: WP ULike <= 5.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-2358 affects WP ULike plugin versions up to 5.0.1, with a medium severity (CVSS 6.4) due to stored XSS. Update to version 5.0.2 to mitigate the risk of script injection by authenticated users.
March 18, 2026
CVE-2025-12473: RTMKit <= 1.6.8 Reflected Cross-Site Scripting via 'themebuilder' Parameter PoC, Patch Analysis & Rule
CVE-2025-12473 affects Rometheme For Elementor plugin versions up to 1.6.8, with a CVSS score of 6.1. Ensure you upgrade to version 2.0.0 to mitigate the reflected XSS vulnerability.
March 18, 2026
CVE-2026-2413: Ally – Web Accessibility & Usability <= 4.0.3 Unauthenticated SQL Injection via URL Path PoC, Patch Analysis & Rule
CVE-2026-2413 affects the Pojo Accessibility plugin (up to v4.0.3) with a high severity (CVSS 7.5) SQL injection vulnerability. Update to v4.1.0 to mitigate risks of unauthorized database access.
March 18, 2026
CVE-2026-1781: MC4WP: Mailchimp for WordPress <= 4.11.1 Missing Authorization to Unauthenticated Arbitrary Subscription Deletion PoC, Patch Analysis & Rule
CVE-2026-1781 affects the Mailchimp For WP plugin (up to v4.11.1) with a CVSS score of 6.5, allowing remote code execution. Upgrade to v4.12.0 to mitigate unauthorized unsubscribe actions.
March 18, 2026
CVE-2026-3453: ProfilePress <= 4.16.11 Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration PoC, Patch Analysis & Rule
CVE-2026-3453 affects the Wp User Avatar plugin (up to version 4.16.11) with a CVSS score of 8.1. Authenticated users can exploit this vulnerability to cancel others' subscriptions. Upgrade to version 4.16.12 to mitigate the risk.
March 18, 2026
CVE-2025-13067: Royal Addons for Elementor <= 1.7.1049 Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass PoC, Patch Analysis & Rule
CVE-2025-13067 affects the Royal Elementor Addons plugin (up to v1.7.1049) with a high severity (CVSS 8.8) file upload vulnerability. Update to v1.7.1050 to mitigate risks of unauthorized file uploads.
March 18, 2026
CVE-2026-2707: weForms <= 1.6.27 Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API PoC, Patch Analysis & Rule
CVE-2026-2707 affects the Weforms plugin for WordPress (up to version 1.6.27) with a medium severity (CVSS 6.4) stored XSS vulnerability. Update to version 1.6.28 to mitigate risks from potential attacks via the REST API.
March 18, 2026
CVE-2026-2324: LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-2324 affects the LatePoint plugin (v5.2.7) with a medium severity (CVSS 6.1) cross-site scripting vulnerability. Upgrade to v5.2.8 to mitigate risks from unauthenticated attackers exploiting nonce validation flaws.
March 18, 2026
CVE-2026-3178: Name Directory <= 1.32.1 Unauthenticated Stored Cross-Site Scripting via 'name_directory_name' PoC, Patch Analysis & Rule
CVE-2026-3178 affects the Name Directory plugin (up to 1.32.1) with a high severity CVSS score of 7.2 due to stored XSS. Upgrade to version 1.33.0 to mitigate risks from unauthenticated script injection.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
