Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 18, 2026

CVE-2026-1824: Infomaniak Connect for OpenID <= 1.0.2 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2026-1824 affects the Infomaniak Connect OpenID plugin (v1.0.2) with a medium severity (CVSS 6.4) stored XSS vulnerability. Authenticated attackers can exploit this flaw, so patching is essential to protect user data.
March 18, 2026

CVE-2026-1825: Show YouTube video <= 1.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-1825 affects the Show YouTube Video plugin for WordPress, with a medium severity CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability in version 1.1, making patching essential.
March 18, 2026

CVE-2026-1805: DA Media GigList <= 1.9.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'list_title' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-1805 affects the Damedia Giglist plugin (up to v1.9.0) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should update to the patched version to mitigate risks from potential script injections.
March 18, 2026

CVE-2026-1820: Media Library Alt Text Editor <= 1.0.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'post_id' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-1820 affects the Media Library Alt Text Editor plugin (v1.0.0) with a medium severity (CVSS 6.4) stored XSS vulnerability. Patching is essential to prevent authenticated attackers from injecting scripts.
March 18, 2026

CVE-2025-8899: Paid Videochat Turnkey Site – HTML5 PPV Live Webcams <= 7.3.20 Authenticated (Author+) Privilege Escalation PoC, Patch Analysis & Rule

CVE-2025-8899 affects the Ppv Live Webcams plugin (up to v7.3.20) with a high severity (CVSS 8.8) privilege escalation vulnerability. Authenticated users can exploit this to register as administrators. Update to the patched version for...
March 18, 2026

CVE-2026-1650: MDJM Event Management <= 1.7.8.1 Missing Authorization to Unauthenticated Arbitrary Custom Event Field Deletion PoC, Patch Analysis & Rule

CVE-2026-1650 affects the Mobile Dj Manager plugin (v1.7.8.1) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized data modification. Update to v1.7.8.2 to mitigate risks.
March 18, 2026

CVE-2026-1823: Consensus Embed <= 1.6 Authenticated (Contributor+) Stored Cross-Site Scripting via 'src' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-1823 affects the Consensus Embed plugin for WordPress (up to v1.6) with a medium severity (CVSS 6.4) stored XSS vulnerability. Authenticated attackers can inject scripts, making patching essential for security.
March 18, 2026

CVE-2025-14353: ZIP Code Based Content Protection <= 1.0.2 Unauthenticated SQL Injection via 'zipcode' Parameter PoC, Patch Analysis & Rule

CVE-2025-14353 affects the Zip Code Based Content Protection plugin for WordPress (up to v1.0.2) with a CVSS score of 7.5. Unauthenticated SQL injection can expose sensitive data; patching is crucial.
March 18, 2026

CVE-2026-1574: MyQtip – easy qTip2 <= 2.0.5 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode PoC, Patch Analysis & Rule

CVE-2026-1574 affects the Myqtip Easy Qtip2 plugin (up to v2.0.5) with a medium severity (CVSS 6.4) due to stored XSS. Users should update to the patched version to mitigate potential script injection risks.
March 18, 2026

CVE-2026-1569: Wueen <= 0.2.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin's Shortcode PoC, Patch Analysis & Rule

CVE-2026-1569 affects the Wueen plugin (up to version 0.2.0) with a medium severity (CVSS 6.4) due to stored XSS vulnerabilities. Ensure to patch to the latest version to mitigate risks from authenticated attacks.
March 18, 2026

CVE-2026-2721: MailArchiver <= 4.4.0 Authenticated (Administrator+) Stored Cross-Site Scripting via Settings PoC, Patch Analysis & Rule

CVE-2026-2721 affects the Mailarchiver plugin (up to version 4.4.0) with a medium severity (CVSS 4.8) stored XSS vulnerability. Upgrade to version 4.5.0 to mitigate risks associated with this issue.
March 18, 2026

CVE-2026-2429: Community Events <= 1.5.8 Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Field PoC, Patch Analysis & Rule

CVE-2026-2429 affects the Community Events plugin for WordPress (up to 1.5.8) with a medium severity (CVSS 4.9) SQL injection vulnerability. Update to version 1.5.9 to mitigate risks from potential data exposure.
March 18, 2026

CVE-2026-2494: ProfileGrid <= 5.9.8.2 Cross-Site Request Forgery to Group Membership Request Approval/Denial PoC, Patch Analysis & Rule

CVE-2026-2494 affects the ProfileGrid User Profiles plugin (up to 5.9.8.2) with a medium severity (CVSS 4.3) CSRF vulnerability. Update to version 5.9.8.3 to mitigate unauthorized group membership actions.
March 18, 2026

CVE-2026-2488: ProfileGrid <= 5.9.8.1 Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion PoC, Patch Analysis & Rule

CVE-2026-2488 affects the ProfileGrid User Profiles plugin (up to version 5.9.8.1) with a CVSS score of 4.3. Authenticated users can delete messages without proper checks. Upgrade to 5.9.8.2 to mitigate this risk.
March 18, 2026

CVE-2026-2431: CM Custom Reports <= 1.2.7 Reflected Cross-Site Scripting via 'date_from' and 'date_to' Parameters PoC, Patch Analysis & Rule

CVE-2026-2431 affects the CM Custom Reports plugin (up to v1.2.7) with a medium severity (CVSS 6.1) XSS vulnerability. Users should upgrade to v1.2.8 to mitigate potential attacks via the 'date_from' and 'date_to' parameters.
March 18, 2026

CVE-2026-2020: JS Archive List <= 6.1.7 Authenticated (Contributor+) PHP Object Injection via 'included' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-2020 affects the Jquery Archive List Widget plugin (up to 6.1.7) with a high severity (CVSS 7.5) PHP Object Injection vulnerability. Upgrade to version 6.2.0 to mitigate risks of unauthorized file access and code execution.
March 18, 2026

CVE-2026-1644: WP Frontend Profile <= 1.3.8 Cross-Site Request Forgery to Unauthorized User Account Approval or Rejection PoC, Patch Analysis & Rule

CVE-2026-1644 affects the WP Front End Profile plugin (up to v1.3.8) with a CVSS score of 4.3. This medium-severity CSRF vulnerability allows attackers to manipulate user registrations. Update to v1.3.9 to mitigate risks.
March 18, 2026

CVE-2026-2722: Stock Ticker <= 3.26.1 Authenticated (Administrator+) Stored Cross-Site Scripting via Template PoC, Patch Analysis & Rule

CVE-2026-2722 affects the Stock Ticker plugin (up to version 3.26.1) with a CVSS score of 4.8. Authenticated attackers can exploit stored XSS due to insufficient input sanitization. Patching is essential for security.
March 18, 2026

CVE-2026-1902: Hammas Calendar <= 1.5.11 Authenticated (Contributor+) Stored Cross-Site Scripting via 'apix' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-1902 affects the Hammas Calendar plugin (up to v1.5.11) with a medium severity (CVSS 6.4) cross-site scripting vulnerability. Update to v1.5.12 to mitigate risks from authenticated attackers injecting scripts.
March 18, 2026

CVE-2026-2371: Greenshift <= 12.8.3 Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load' PoC, Patch Analysis & Rule

CVE-2026-2371 affects the Greenshift Animation And Page Builder Blocks plugin (up to v12.8.3) with a medium severity (CVSS 5.3) IDOR vulnerability. Update to v12.8.4 to mitigate unauthorized content access.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works