
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1454: Responsive Contact Form Builder & Lead Generation Plugin <= 2.0.1 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-1454 affects the Lead Form Builder plugin for WordPress (up to v2.0.1) with a CVSS score of 7.2. Ensure you update to v2.0.3 to mitigate stored XSS risks from untrusted form submissions.
March 18, 2026
CVE-2026-2724: Unlimited Elements For Elementor <= 2.0.5 Unauthenticated Stored Cross-Site Scripting via Form Entry Fields PoC, Patch Analysis & Rule
CVE-2026-2724 affects Unlimited Elements For Elementor (up to v2.0.5) with a CVSS score of 7.2. This high-severity XSS vulnerability allows unauthenticated attackers to inject scripts. Update to the patched version to mitigate risks.
March 18, 2026
CVE-2026-3903: Modular Connector <= 2.5.1 Cross-Site Request Forgery via postConfirmOauth PoC, Patch Analysis & Rule
CVE-2026-3903 affects the Modular Connector plugin (up to v2.5.1) with a medium severity (CVSS 4.3) CSRF vulnerability. Update to v2.6.0 to mitigate risks from unauthenticated attackers exploiting OAuth connections.
March 18, 2026
CVE-2026-27091: UiPress lite | Effortless custom dashboards, admin themes and pages <= 3.5.09 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-27091 affects the Uipress Lite plugin (v3.5.09) with a medium severity (CVSS 4.3) vulnerability. Authenticated users can exploit this flaw for unauthorized actions. Update to the patched version to mitigate risks.
March 18, 2026
CVE-2026-2569: Dear Flipbook <= 2.4.20 Authenticated (Auhtor+) Stored Cross-Site Scripting via PDF Page Labels PoC, Patch Analysis & Rule
CVE-2026-2569 affects the 3d Flipbook Dflip Lite plugin (up to v2.4.20) with a CVSS score of 6.4. Authenticated attackers can exploit stored XSS vulnerabilities, so update to v2.4.27 to mitigate risks.
March 18, 2026
CVE-2026-1261: MetForm Pro <= 3.9.6 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-1261 affects Metform Pro plugin versions up to 3.9.6, posing a high severity risk (CVSS 7.2) due to stored XSS vulnerabilities. Users should update to the patched version to mitigate potential attacks.
March 18, 2026
CVE-2026-3228: NextScripts: Social Networks Auto-Poster <= 4.4.6 Authenticated (Contributor+) Stored Cross-Site Scripting via 'nxs_fbembed' Shortcode PoC, Patch Analysis & Rule
CVE-2026-3228 affects the NextScripts Social Networks Auto-Poster plugin (up to 4.4.6) with a medium severity CVSS of 6.4. Ensure proper input sanitization to mitigate stored XSS risks.
March 18, 2026
CVE-2026-0953: Tutor LMS Pro <= 3.9.5 Authentication Bypass via Social Login PoC, Patch Analysis & Rule
CVE-2026-0953 affects Tutor Pro plugin versions up to 3.9.5, allowing critical authentication bypass (CVSS 9.8). Update to the patched version to mitigate the risk of unauthorized access.
March 18, 2026
CVE-2026-1919: Booktics <= 1.0.16 Missing Authorization to Get Items via REST API endpoints PoC, Patch Analysis & Rule
CVE-2026-1919 affects the Booktics plugin (up to version 1.0.16) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized data access. Update to version 1.0.17 to mitigate this risk.
March 18, 2026
CVE-2026-1920: Booktics <= 1.0.16 Missing Authorization to Addon Plugin Installation PoC, Patch Analysis & Rule
CVE-2026-1920 affects the Booktics plugin (up to v1.0.16) with a CVSS score of 5.3. Unauthenticated attackers can exploit this vulnerability to install addon plugins. Update to v1.0.17 to mitigate risks.
March 18, 2026
CVE-2026-3585: The Events Calendar <= 6.15.17 Authenticated (Author+) Arbitrary File Read via ajax_create_import PoC, Patch Analysis & Rule
CVE-2026-3585 affects The Events Calendar plugin (up to 6.15.17) with a CVSS score of 7.5. This high-severity file upload vulnerability allows authenticated attackers to access sensitive server files. Update to 6.15.17.1 to mitigate.
March 18, 2026
CVE-2025-14675: Meta Box <= 5.11.1 Authenticated (Contributor+) Arbitrary File Deletion PoC, Patch Analysis & Rule
CVE-2025-14675 affects the Meta Box plugin (up to v5.11.1) with a high severity score of 7.2. Patching to v5.11.2 is crucial to mitigate the risk of arbitrary file deletion and potential remote code execution.
March 18, 2026
CVE-2026-22520: Handmade Framework <= 3.9 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-22520 affects the Handmade Framework plugin for WordPress (up to version 3.9) with a medium severity (CVSS 6.1) cross-site scripting vulnerability. Ensure you update to the patched version to mitigate potential exploitation.
March 18, 2026
CVE-2026-2433: RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.11 Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage PoC, Patch Analysis & Rule
CVE-2026-2433 affects the Wp Rss Aggregator plugin (up to 5.0.11) with a medium severity (CVSS 6.1) cross-site scripting vulnerability. Update to version 5.0.12 to mitigate the risk of unauthorized JavaScript execution.
March 18, 2026
CVE-2026-1074: WP App Bar <= 1.5 Unauthenticated Stored Cross-Site Scripting via 'app-bar-features' Parameter PoC, Patch Analysis & Rule
CVE-2026-1074 affects the WP App Bar plugin (up to version 1.5) with a CVSS score of 7.2. This high-severity stored XSS vulnerability allows attackers to inject scripts, emphasizing the need for immediate patching.
March 18, 2026
CVE-2026-1085: True Ranker <= 2.2.9 Cross-Site Request Forgery to Unauthorized True Ranker Disconnection PoC, Patch Analysis & Rule
CVE-2026-1085 affects the Seo Local Rank plugin (v2.2.9) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure you update to the patched version to prevent unauthorized account disconnections.
March 18, 2026
CVE-2026-2420: LotekMedia Popup Form <= 1.0.6 Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings PoC, Patch Analysis & Rule
CVE-2026-2420 affects the LotekMedia Popup Form plugin (v1.0.6) with a medium severity CVSS score of 4.4. Ensure to patch to the latest version to mitigate stored XSS risks from authenticated attackers.
March 18, 2026
CVE-2026-1071: Carta Online <= 2.13.0 Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings PoC, Patch Analysis & Rule
CVE-2026-1071 affects the Carta Online plugin for WordPress (up to v2.13.0) with a medium severity (CVSS 4.4) stored XSS vulnerability. Authenticated admins can inject scripts, impacting multi-site setups. Patching is essential.
March 18, 2026
CVE-2026-1086: Font Pairing Preview For Landing Pages <= 1.3 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule
CVE-2026-1086 affects the Wp Font Pairing Preview plugin (v1.3) with a medium severity (CVSS 4.3) due to cross-site request forgery. Ensure you update to the patched version to mitigate unauthorized settings changes.
March 18, 2026
CVE-2026-1073: Purchase Button For Affiliate Link <= 1.0.2 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule
CVE-2026-1073 affects the Purchase Button plugin for WordPress (v1.0.2) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure to patch to prevent unauthorized setting modifications by attackers.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
