Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-3231: Checkout Field Editor (Checkout Manager) for WooCommerce <= 2.1.7 Unauthenticated Stored Cross-Site Scripting via Block Checkout Custom Radio Field PoC, Patch Analysis & Rule

CVE-2026-3231 affects Woo Checkout Field Editor Pro (up to v2.1.7) with a high severity CVSS score of 7.2. Unauthenticated attackers can exploit a stored XSS vulnerability. Upgrade to v2.1.8 to mitigate risks.
March 18, 2026

CVE-2026-3492: Gravity Forms <= 2.9.28.1 Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title PoC, Patch Analysis & Rule

CVE-2026-3492 affects Gravity Forms versions up to 2.9.28.1, with a CVSS score of 6.4. It allows authenticated users to exploit stored XSS vulnerabilities. Update to the latest version to mitigate risks.
March 18, 2026

CVE-2026-1993: ExactMetrics 7.1.0 9.0.2 Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update PoC, Patch Analysis & Rule

CVE-2026-1993 affects the Google Analytics Dashboard for WP plugin (versions 7.1.0 to 9.0.2) with a CVSS score of 8.8. Update to version 9.0.3 to mitigate improper privilege management risks.
March 18, 2026

CVE-2026-3226: LearnPress <= 4.3.2.8 Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering PoC, Patch Analysis & Rule

CVE-2026-3226 affects the LearnPress plugin (up to v4.3.2.8) with a medium severity (CVSS 4.3). It allows authenticated users to trigger unauthorized email notifications. Update to v4.3.3 to mitigate this risk.
March 18, 2026

CVE-2026-2466: DukaPress <= 3.2.4 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-2466 affects the DukaPress plugin (up to version 3.2.4) with a high severity CVSS score of 7.2. Unauthenticated attackers can exploit this stored XSS vulnerability, making patching essential for user security.
March 18, 2026

CVE-2026-1992: ExactMetrics 8.6.0 9.0.2 Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation PoC, Patch Analysis & Rule

CVE-2026-1992 affects the Google Analytics Dashboard for WP plugin (versions 8.6.0 to 9.0.2) with a CVSS score of 8.8. Patch to version 9.0.3 to mitigate remote code execution risks from insecure direct object reference.
March 18, 2026

CVE-2026-2917: Happy Addons for Elementor <= 3.21.0 Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter PoC, Patch Analysis & Rule

CVE-2026-2917 affects the Happy Elementor Addons plugin (up to v3.21.0) with a medium severity (CVSS 5.4) vulnerability. Update to v3.21.1 to mitigate risks of unauthorized content cloning by authenticated users.
March 18, 2026

CVE-2026-3496: JetBooking <= 4.0.3 Unauthenticated SQL Injection via 'check_in_date' Parameter PoC, Patch Analysis & Rule

CVE-2026-3496 affects the Jet Booking plugin (up to version 4.0.3) with a high severity score of 7.5. This SQL injection vulnerability allows unauthenticated attackers to extract sensitive data. Ensure you update to the patched version.
March 18, 2026

CVE-2026-3222: WP Maps <= 4.9.1 Unauthenticated SQL Injection via 'location_id' Parameter PoC, Patch Analysis & Rule

CVE-2026-3222 affects the WP Google Map Plugin (up to v4.9.1) with a high severity CVSS of 7.5 due to SQL injection vulnerabilities. Upgrade to v4.9.2 to mitigate risks from unauthenticated attacks.
March 18, 2026

CVE-2026-2918: Happy Addons for Elementor <= 3.21.0 Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions PoC, Patch Analysis & Rule

CVE-2026-2918 affects Happy Elementor Addons plugin versions up to 3.21.0, with a CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability; update to version 3.21.1 to mitigate risks.
March 18, 2026

CVE-2026-2358: WP ULike <= 5.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-2358 affects WP ULike plugin versions up to 5.0.1, with a medium severity (CVSS 6.4) due to stored XSS. Update to version 5.0.2 to mitigate the risk of script injection by authenticated users.
March 18, 2026

CVE-2025-12473: RTMKit <= 1.6.8 Reflected Cross-Site Scripting via 'themebuilder' Parameter PoC, Patch Analysis & Rule

CVE-2025-12473 affects Rometheme For Elementor plugin versions up to 1.6.8, with a CVSS score of 6.1. Ensure you upgrade to version 2.0.0 to mitigate the reflected XSS vulnerability.
March 18, 2026

CVE-2026-2413: Ally – Web Accessibility & Usability <= 4.0.3 Unauthenticated SQL Injection via URL Path PoC, Patch Analysis & Rule

CVE-2026-2413 affects the Pojo Accessibility plugin (up to v4.0.3) with a high severity (CVSS 7.5) SQL injection vulnerability. Update to v4.1.0 to mitigate risks of unauthorized database access.
March 18, 2026

CVE-2026-1781: MC4WP: Mailchimp for WordPress <= 4.11.1 Missing Authorization to Unauthenticated Arbitrary Subscription Deletion PoC, Patch Analysis & Rule

CVE-2026-1781 affects the Mailchimp For WP plugin (up to v4.11.1) with a CVSS score of 6.5, allowing remote code execution. Upgrade to v4.12.0 to mitigate unauthorized unsubscribe actions.
March 18, 2026

CVE-2026-3453: ProfilePress <= 4.16.11 Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration PoC, Patch Analysis & Rule

CVE-2026-3453 affects the Wp User Avatar plugin (up to version 4.16.11) with a CVSS score of 8.1. Authenticated users can exploit this vulnerability to cancel others' subscriptions. Upgrade to version 4.16.12 to mitigate the risk.
March 18, 2026

CVE-2025-13067: Royal Addons for Elementor <= 1.7.1049 Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass PoC, Patch Analysis & Rule

CVE-2025-13067 affects the Royal Elementor Addons plugin (up to v1.7.1049) with a high severity (CVSS 8.8) file upload vulnerability. Update to v1.7.1050 to mitigate risks of unauthorized file uploads.
March 18, 2026

CVE-2026-2707: weForms <= 1.6.27 Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API PoC, Patch Analysis & Rule

CVE-2026-2707 affects the Weforms plugin for WordPress (up to version 1.6.27) with a medium severity (CVSS 6.4) stored XSS vulnerability. Update to version 1.6.28 to mitigate risks from potential attacks via the REST API.
March 18, 2026

CVE-2026-2324: LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting PoC, Patch Analysis & Rule

CVE-2026-2324 affects the LatePoint plugin (v5.2.7) with a medium severity (CVSS 6.1) cross-site scripting vulnerability. Upgrade to v5.2.8 to mitigate risks from unauthenticated attackers exploiting nonce validation flaws.
March 18, 2026

CVE-2026-3178: Name Directory <= 1.32.1 Unauthenticated Stored Cross-Site Scripting via 'name_directory_name' PoC, Patch Analysis & Rule

CVE-2026-3178 affects the Name Directory plugin (up to 1.32.1) with a high severity CVSS score of 7.2 due to stored XSS. Upgrade to version 1.33.0 to mitigate risks from unauthenticated script injection.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works