Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

June 25, 2026

CVE-2026-56023: UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-56023 affects the UPI QR Code Payment For WooCommerce plugin (up to v1.6.2) with a CVSS score of 4.3. Patch to v1.6.3 to mitigate unauthorized access to sensitive payment settings.
June 25, 2026

CVE-2026-54844: CheckView – Form & Checkout Testing <= 2.1.0 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-54844 affects the CheckView plugin for WordPress (up to version 2.1.0) due to a missing capability check, allowing unauthorized access. Upgrade to version 2.2.0 to mitigate this medium severity vulnerability.
June 25, 2026

CVE-2026-56010: Abandoned Cart Pro for WooCommerce <= 10.4.0 Authenticated (Subscriber+) Privilege Escalation PoC, Patch Analysis & Rule

CVE-2026-56010 affects the WooCommerce Abandon Cart Pro plugin (up to version 10.4.0) with a CVSS score of 8.8. Authenticated users can escalate privileges to admin, highlighting the need for immediate patching.
June 25, 2026

CVE-2026-54840: Newsletters <= 4.13 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-54840 affects the Newsletters Lite plugin for WordPress (up to v4.13) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Update to v4.14 to mitigate this risk.
June 24, 2026

CVE-2026-12077: Dokan Pro <= 5.0.4 Unauthenticated SQL Injection via 'latitude' and 'longitude' Parameters PoC, Patch Analysis & Rule

CVE-2026-12077 affects the Dokan Pro plugin for WordPress (up to v5.0.4) with a CVSS score of 7.5. This high-severity SQL injection vulnerability allows unauthenticated attackers to extract sensitive data. Users should update to the...
June 24, 2026

CVE-2026-2508: Gravity Forms Booking <= 2.7.1 Authenticated (Subscriber+) Time-Based SQL Injection via 'staff_id' PoC, Patch Analysis & Rule

CVE-2026-2508 affects the Gf Bookings Premium plugin (up to 2.7.1) with a medium severity (CVSS 6.5) SQL injection vulnerability. Authenticated attackers can extract sensitive data, so patching is essential.
June 24, 2026

CVE-2026-12937: Tourfic <= 2.22.7 Unauthenticated SQL Injection via 'post_id' Parameter PoC, Patch Analysis & Rule

CVE-2026-12937 affects the Tourfic plugin for WordPress (up to version 2.22.7), allowing unauthenticated SQL injection with a CVSS score of 7.5. Update to version 2.22.8 to mitigate the risk of sensitive data exposure.
June 24, 2026

CVE-2026-12079: Dokan Pro <= 5.0.4 Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter PoC, Patch Analysis & Rule

CVE-2026-12079 affects the Dokan Pro plugin for WordPress (up to v5.0.4) with a medium severity (CVSS 6.5) SQL injection vulnerability. Authenticated attackers can exploit this to extract sensitive database information. Patching is...
June 24, 2026

CVE-2026-9178: WP Forms Connector <= 1.8 Missing Authorization to Unauthenticated Information Exposure via 'user/list' REST Endpoint PoC, Patch Analysis & Rule

CVE-2026-9178 affects the WP Forms Connector plugin (up to v1.8) with a CVSS score of 7.5. Unauthenticated attackers can access sensitive user data. Update to the patched version to mitigate this risk.
June 24, 2026

CVE-2026-10833: Gutenberg Essential Blocks Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute PoC, Patch Analysis & Rule

CVE-2026-10833 affects the Essential Blocks plugin for WordPress (up to version 6.1.4) with a CVSS score of 6.4. Patch to version 6.2.0 to mitigate Stored XSS risks from authenticated attackers.
June 24, 2026

CVE-2026-9179: WP Forms Connector <= 1.8 Unauthenticated SQL Injection via 'order' Parameter PoC, Patch Analysis & Rule

CVE-2026-9179 affects the WP Forms Connector plugin (up to version 1.8) with a high severity CVSS score of 7.5. Unauthenticated SQL injection can expose sensitive data; patching is essential to mitigate risks.
June 24, 2026

CVE-2026-9183: 24liveblog <= 2.2 Authenticated (Contributor+) Exposure of Sensitive Information via Block Editor Script Localization PoC, Patch Analysis & Rule

CVE-2026-9183 affects the 24liveblog plugin version 2.2, exposing sensitive integration credentials to authenticated users with contributor access. Patch to mitigate this medium-severity vulnerability is recommended.
June 24, 2026

CVE-2026-9184: 24liveblog <= 2.2 Missing Authorization to Authenticated (Author+) Settings Modification via update_lb24_token AJAX action PoC, Patch Analysis & Rule

CVE-2026-9184 affects the 24liveblog plugin (up to v2.2) with a CVSS score of 4.3. Authenticated attackers can modify user settings due to missing capability checks. Update to the patched version to mitigate this risk.
June 24, 2026

CVE-2026-8690: RentMy Real-Time Rental Management Plugin <= 4.0.4.1 Missing Authorization to Unauthenticated Settings Update via rentmy_cdn_request AJAX Action PoC, Patch Analysis & Rule

CVE-2026-8690 affects the Rentmy Online Rental Shop plugin (up to 4.0.4.1) with a CVSS score of 5.3. This medium severity vulnerability allows unauthenticated users to bypass authorization and manipulate event records. Update to the...
June 24, 2026

CVE-2026-8617: SearchPlus <= 1.7.1 Missing Authorization to Unauthenticated Settings Modification and Deletion via searchplus_save_token & searchplus_reset_token AJAX Actions PoC, Patch Analysis & Rule

CVE-2026-8617 affects the SearchPlus plugin for WordPress (up to v1.7.1) with a medium severity CVSS score of 5.3. Unauthenticated attackers can modify or delete account tokens; ensure you update to the patched version.
June 24, 2026

CVE-2026-8905: Osiris Signature Banner <= 0.5 Cross-Site Request Forgery to Stored Cross-Site Scripting via 'prepend_text' Parameter PoC, Patch Analysis & Rule

The Osiris Signature Banner plugin for WordPress (CVE-2026-8905) is vulnerable to cross-site request forgery, allowing unauthenticated attackers to inject scripts. Update to the patched version to mitigate this medium severity issue.
June 24, 2026

CVE-2026-8614: Assistio <= 1.1.2 Missing Authorization to Authenticated (Subscriber+) Plugin Settings Deletion via assistio_plugin_delete_assistio_settings AJAX Action PoC, Patch Analysis & Rule

CVE-2026-8614 affects the Assistio WordPress plugin (up to version 1.1.2) with a CVSS score of 4.3. Authenticated users can delete critical settings, impacting integration with Assistio bot. Patching is recommended.
June 24, 2026

CVE-2026-8688: Advance Nav Menu Manager <= 1.3 Missing Authorization to Authenticated (Subscriber+) Nav Menu Item Modification via anmm_save_menu_data AJAX Action PoC, Patch Analysis & Rule

CVE-2026-8688 affects the Advance Nav Menu Manager plugin for WordPress (up to version 1.3) with a medium severity (CVSS 4.3) authentication bypass. Users should update to the latest version to mitigate unauthorized menu modifications.
June 24, 2026

CVE-2026-7617: Secufor_OAuth <= 1.0.7 Missing Authorization to Unauthenticated Account Logout via 'secuforoauth_unregister_action' AJAX Action PoC, Patch Analysis & Rule

CVE-2026-7617 affects the Wpoauth plugin (up to version 1.0.7) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Users should update to the patched version to mitigate risks.
June 24, 2026

CVE-2026-12417: SignUp & SignIn <= 1.0.0 Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account Takeover PoC, Patch Analysis & Rule

CVE-2026-12417 affects the Signup Signin plugin for WordPress (v1.0.0) with a critical CVSS score of 9.8. Unauthenticated attackers can exploit this vulnerability to bypass authentication and take over accounts. Patching is essential.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works