
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2026-2589: Greenshift – animation and page builder blocks <= 12.8.3 Unauthenticated Sensitive Information Exposure via Settings Backup PoC, Patch Analysis & Rule
CVE-2026-2589 affects the Greenshift Animation And Page Builder Blocks plugin (up to version 12.8.3) with a CVSS score of 5.3. Update to version 12.8.4 to mitigate sensitive data exposure risks.
March 18, 2026
CVE-2026-1981: Winston AI <= 0.0.3 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion PoC, Patch Analysis & Rule
CVE-2026-1981 affects the Winston Ai Wp plugin up to version 0.0.3, allowing unauthorized data modification by authenticated users. Upgrade to version 0.0.4 to mitigate this medium-severity vulnerability.
March 18, 2026
CVE-2026-2593: Greenshift – animation and page builder blocks <= 12.8.5 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-2593 affects the Greenshift Animation And Page Builder Blocks plugin (up to 12.8.5) with a medium severity (CVSS 6.4) XSS vulnerability. Users should upgrade to version 12.8.6 to mitigate potential attacks.
March 18, 2026
CVE-2026-3459: Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.5 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule
CVE-2026-3459 affects the Drag And Drop Multiple File Upload Contact Form 7 plugin, with a CVSS score of 8.1. Update to version 1.3.9.6 to mitigate the high-risk file upload vulnerability.
March 18, 2026
CVE-2026-2830: WP All Import <= 4.0.0 Reflected Cross-Site Scripting via 'filepath' PoC, Patch Analysis & Rule
CVE-2026-2830 affects WP All Import plugin versions up to 4.0.0, with a CVSS score of 6.1. It allows reflected XSS due to insufficient input sanitization. Update to version 4.0.1 to mitigate this vulnerability.
March 18, 2026
CVE-2026-27095: Bus Ticket Booking with Seat Reservation <= 5.6.2 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
CVE-2026-27095 affects the Bus Ticket Booking With Seat Reservation plugin (up to 5.6.2) with a CVSS score of 8.1. This high-severity file upload vulnerability allows unauthenticated attackers to exploit PHP Object Injection. Patching...
March 18, 2026
CVE-2026-22485: My Album Gallery <= 1.0.4 Authenticated (Subscriber+) Arbitrary File Deletion PoC, Patch Analysis & Rule
CVE-2026-22485 affects the My Album Gallery plugin (v1.0.4) with a high severity (CVSS 8.1) file upload vulnerability, allowing authenticated users to delete arbitrary files. Update to the patched version to mitigate risks.
March 18, 2026
CVE-2026-22480: WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More <= 2.3.3 Authenticated (Shop manager+) PHP Object Injection PoC, Patch Analysis & Rule
CVE-2026-22480 affects the Webtoffee Product Feed plugin for WordPress (versions up to 2.3.3) with a medium severity CVSS of 6.6. Users should upgrade to version 2.3.4 to mitigate the PHP object injection vulnerability.
March 18, 2026
CVE-2026-22491: My auctions allegro <= 3.6.34 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-22491 affects the My Auctions Allegro Free Edition plugin (up to version 3.6.34) with a medium severity CVSS score of 6.1. Users should update to the patched version to mitigate the reflected XSS risk.
March 18, 2026
CVE-2026-3072: Media Library Assistant <= 3.33 Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification PoC, Patch Analysis & Rule
CVE-2026-3072 affects the Media Library Assistant plugin (up to v3.33) with a medium severity (CVSS 4.3) vulnerability allowing unauthorized data modification. Upgrade to v3.34 to mitigate this risk.
March 18, 2026
CVE-2025-69347: Subscription for WooCommerce – WordPress Recurring Payments Plugin <= 1.8.10 Authenticated (Customer+) Insecure Direct Object Reference PoC, Patch Analysis & Rule
CVE-2025-69347 affects the Subscription for WooCommerce plugin (up to v1.8.10) with a medium severity (CVSS 4.3) remote code execution vulnerability. Users should patch to the latest version to mitigate unauthorized access risks.
March 18, 2026
CVE-2026-2893: Page and Post Clone <= 6.3 Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter PoC, Patch Analysis & Rule
CVE-2026-2893 affects the Page Or Post Clone plugin for WordPress, with a medium severity CVSS score of 6.5. Users should update to the patched version to mitigate SQL injection risks from authenticated attackers.
March 18, 2026
CVE-2026-22484: Lisfinity Core Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.5.0 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-22484 affects the Lisfinity Core plugin (v1.5.0) with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated attackers to extract sensitive data. Update to the patched version to mitigate risks.
March 18, 2026
CVE-2026-2365: Fluent Forms Pro <= 6.1.17 Unauthenticated Stored Cross-Site Scripting via Draft Form Submission PoC, Patch Analysis & Rule
CVE-2026-2365 affects Fluent Forms Pro (up to 6.1.17) with a CVSS score of 7.2. Unauthenticated attackers can exploit stored XSS via a public AJAX endpoint. Update to the patched version to mitigate this risk.
March 18, 2026
CVE-2026-2899: Fluent Forms Pro Add On Pack <= 6.1.17 Missing Authorization to Unauthenticated Arbitrary Attachment Deletion PoC, Patch Analysis & Rule
CVE-2026-2899 affects the Fluent Forms Pro Add On Pack plugin (up to version 6.1.17) with a medium severity (CVSS 6.5) vulnerability allowing unauthenticated users to delete media files. Update to the patched version to mitigate this risk.
March 18, 2026
CVE-2026-3034: OoohBoi Steroids for Elementor <= 2.1.24 Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls PoC, Patch Analysis & Rule
CVE-2026-3034 affects the Ooohboi Steroids for Elementor plugin (up to v2.1.24) with a medium severity (CVSS 6.4) stored XSS vulnerability. Update to v2.1.25 to mitigate the risk of arbitrary script injection by authenticated users.
March 18, 2026
CVE-2025-68515: WP Booking System – Booking Calendar <= 2.0.19.12 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
CVE-2025-68515 affects the WP Booking System plugin (up to version 2.0.19.12) with a CVSS score of 5.3, exposing sensitive data to unauthenticated users. Upgrade to version 2.0.19.13 to mitigate this vulnerability.
March 18, 2026
CVE-2026-2599: Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 Unauthenticated PHP Object Injection via 'download_csv' PoC, Patch Analysis & Rule
CVE-2026-2599 affects the Contact Form Entries plugin (up to 1.4.7) with a critical CVSS score of 9.8 due to a file upload vulnerability. Update to 1.4.8 to mitigate risks from potential PHP Object Injection.
March 18, 2026
CVE-2026-3352: Easy PHP Settings <= 1.0.4 Authenticated (Administrator+) PHP Code Injection via 'wp_memory_limit' Setting PoC, Patch Analysis & Rule
CVE-2026-3352 affects Easy Php Settings plugin versions up to 1.0.4, allowing PHP code injection with a CVSS score of 7.2. Update to version 1.0.5 to mitigate this high-severity vulnerability.
March 18, 2026
CVE-2025-69411: ionCube Tester Plus <= 1.3 Unauthenticated Arbitrary File Download PoC, Patch Analysis & Rule
CVE-2025-69411 affects the ionCube Tester Plus plugin (v1.3) with a critical CVSS score of 9.1 due to a path traversal vulnerability. Upgrade to v1.4 to mitigate unauthorized file access risks.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
