
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-1824: Infomaniak Connect for OpenID <= 1.0.2 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
CVE-2026-1824 affects the Infomaniak Connect OpenID plugin (v1.0.2) with a medium severity (CVSS 6.4) stored XSS vulnerability. Authenticated attackers can exploit this flaw, so patching is essential to protect user data.
March 18, 2026
CVE-2026-1825: Show YouTube video <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1825 affects the Show YouTube Video plugin for WordPress, with a medium severity CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability in version 1.1, making patching essential.
March 18, 2026
CVE-2026-1805: DA Media GigList <= 1.9.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'list_title' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1805 affects the Damedia Giglist plugin (up to v1.9.0) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should update to the patched version to mitigate risks from potential script injections.
March 18, 2026
CVE-2026-1820: Media Library Alt Text Editor <= 1.0.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'post_id' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1820 affects the Media Library Alt Text Editor plugin (v1.0.0) with a medium severity (CVSS 6.4) stored XSS vulnerability. Patching is essential to prevent authenticated attackers from injecting scripts.
March 18, 2026
CVE-2025-8899: Paid Videochat Turnkey Site – HTML5 PPV Live Webcams <= 7.3.20 Authenticated (Author+) Privilege Escalation PoC, Patch Analysis & Rule
CVE-2025-8899 affects the Ppv Live Webcams plugin (up to v7.3.20) with a high severity (CVSS 8.8) privilege escalation vulnerability. Authenticated users can exploit this to register as administrators. Update to the patched version for...
March 18, 2026
CVE-2026-1650: MDJM Event Management <= 1.7.8.1 Missing Authorization to Unauthenticated Arbitrary Custom Event Field Deletion PoC, Patch Analysis & Rule
CVE-2026-1650 affects the Mobile Dj Manager plugin (v1.7.8.1) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized data modification. Update to v1.7.8.2 to mitigate risks.
March 18, 2026
CVE-2026-1823: Consensus Embed <= 1.6 Authenticated (Contributor+) Stored Cross-Site Scripting via 'src' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1823 affects the Consensus Embed plugin for WordPress (up to v1.6) with a medium severity (CVSS 6.4) stored XSS vulnerability. Authenticated attackers can inject scripts, making patching essential for security.
March 18, 2026
CVE-2025-14353: ZIP Code Based Content Protection <= 1.0.2 Unauthenticated SQL Injection via 'zipcode' Parameter PoC, Patch Analysis & Rule
CVE-2025-14353 affects the Zip Code Based Content Protection plugin for WordPress (up to v1.0.2) with a CVSS score of 7.5. Unauthenticated SQL injection can expose sensitive data; patching is crucial.
March 18, 2026
CVE-2026-1574: MyQtip – easy qTip2 <= 2.0.5 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode PoC, Patch Analysis & Rule
CVE-2026-1574 affects the Myqtip Easy Qtip2 plugin (up to v2.0.5) with a medium severity (CVSS 6.4) due to stored XSS. Users should update to the patched version to mitigate potential script injection risks.
March 18, 2026
CVE-2026-1569: Wueen <= 0.2.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin's Shortcode PoC, Patch Analysis & Rule
CVE-2026-1569 affects the Wueen plugin (up to version 0.2.0) with a medium severity (CVSS 6.4) due to stored XSS vulnerabilities. Ensure to patch to the latest version to mitigate risks from authenticated attacks.
March 18, 2026
CVE-2026-2721: MailArchiver <= 4.4.0 Authenticated (Administrator+) Stored Cross-Site Scripting via Settings PoC, Patch Analysis & Rule
CVE-2026-2721 affects the Mailarchiver plugin (up to version 4.4.0) with a medium severity (CVSS 4.8) stored XSS vulnerability. Upgrade to version 4.5.0 to mitigate risks associated with this issue.
March 18, 2026
CVE-2026-2429: Community Events <= 1.5.8 Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Field PoC, Patch Analysis & Rule
CVE-2026-2429 affects the Community Events plugin for WordPress (up to 1.5.8) with a medium severity (CVSS 4.9) SQL injection vulnerability. Update to version 1.5.9 to mitigate risks from potential data exposure.
March 18, 2026
CVE-2026-2494: ProfileGrid <= 5.9.8.2 Cross-Site Request Forgery to Group Membership Request Approval/Denial PoC, Patch Analysis & Rule
CVE-2026-2494 affects the ProfileGrid User Profiles plugin (up to 5.9.8.2) with a medium severity (CVSS 4.3) CSRF vulnerability. Update to version 5.9.8.3 to mitigate unauthorized group membership actions.
March 18, 2026
CVE-2026-2488: ProfileGrid <= 5.9.8.1 Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion PoC, Patch Analysis & Rule
CVE-2026-2488 affects the ProfileGrid User Profiles plugin (up to version 5.9.8.1) with a CVSS score of 4.3. Authenticated users can delete messages without proper checks. Upgrade to 5.9.8.2 to mitigate this risk.
March 18, 2026
CVE-2026-2431: CM Custom Reports <= 1.2.7 Reflected Cross-Site Scripting via 'date_from' and 'date_to' Parameters PoC, Patch Analysis & Rule
CVE-2026-2431 affects the CM Custom Reports plugin (up to v1.2.7) with a medium severity (CVSS 6.1) XSS vulnerability. Users should upgrade to v1.2.8 to mitigate potential attacks via the 'date_from' and 'date_to' parameters.
March 18, 2026
CVE-2026-2020: JS Archive List <= 6.1.7 Authenticated (Contributor+) PHP Object Injection via 'included' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-2020 affects the Jquery Archive List Widget plugin (up to 6.1.7) with a high severity (CVSS 7.5) PHP Object Injection vulnerability. Upgrade to version 6.2.0 to mitigate risks of unauthorized file access and code execution.
March 18, 2026
CVE-2026-1644: WP Frontend Profile <= 1.3.8 Cross-Site Request Forgery to Unauthorized User Account Approval or Rejection PoC, Patch Analysis & Rule
CVE-2026-1644 affects the WP Front End Profile plugin (up to v1.3.8) with a CVSS score of 4.3. This medium-severity CSRF vulnerability allows attackers to manipulate user registrations. Update to v1.3.9 to mitigate risks.
March 18, 2026
CVE-2026-2722: Stock Ticker <= 3.26.1 Authenticated (Administrator+) Stored Cross-Site Scripting via Template PoC, Patch Analysis & Rule
CVE-2026-2722 affects the Stock Ticker plugin (up to version 3.26.1) with a CVSS score of 4.8. Authenticated attackers can exploit stored XSS due to insufficient input sanitization. Patching is essential for security.
March 18, 2026
CVE-2026-1902: Hammas Calendar <= 1.5.11 Authenticated (Contributor+) Stored Cross-Site Scripting via 'apix' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-1902 affects the Hammas Calendar plugin (up to v1.5.11) with a medium severity (CVSS 6.4) cross-site scripting vulnerability. Update to v1.5.12 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026
CVE-2026-2371: Greenshift <= 12.8.3 Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load' PoC, Patch Analysis & Rule
CVE-2026-2371 affects the Greenshift Animation And Page Builder Blocks plugin (up to v12.8.3) with a medium severity (CVSS 5.3) IDOR vulnerability. Update to v12.8.4 to mitigate unauthorized content access.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
