Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

June 24, 2026

CVE-2026-8705: ClearSale Total <= 3.4.2 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2026-8705 affects the ClearSale Total plugin for WordPress (up to 3.4.2) with a CVSS score of 7.5. This high-severity SQL injection allows unauthenticated attackers to extract sensitive data; patch immediately.
June 24, 2026

CVE-2026-12416: Invoice Generator <= 1.0.0 Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter PoC, Patch Analysis & Rule

CVE-2026-12416 affects the Invoice Creator plugin (version 1.0.0) with a critical CVSS score of 9.8, allowing unauthenticated account takeover. Users should patch immediately to secure their sites.
June 24, 2026

CVE-2026-6292: MP Customize Login Page <= 1.0 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

CVE-2026-6292 affects the MP Customize Login Page plugin for WordPress (v1.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Ensure you update to the patched version to prevent unauthorized changes by attackers.
June 24, 2026

CVE-2026-10092: Cincopa video and media plug-in <= 1.163 Unauthenticated Stored Cross-Site Scripting via cincopa Shortcode in Post Comments PoC, Patch Analysis & Rule

CVE-2026-10092 affects the Video Playlist And Gallery Plugin for WordPress (up to 1.163) with a CVSS score of 7.2. Unauthenticated attackers can exploit this XSS vulnerability, so ensure you update to the patched version.
June 23, 2026

CVE-2026-11370: WP Meta SEO <= 4.5.18 Authenticated (Contributor+) Server-Side Request Forgery via 'new_link' Parameter PoC, Patch Analysis & Rule

CVE-2026-11370 affects the WP Meta SEO plugin (up to version 4.5.18) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit it for SSRF, making it essential to patch or implement WAF coverage.
June 23, 2026

CVE-2026-9620: WP Latest Posts <= 5.0.11 Authenticated (Author+) Stored Cross-Site Scripting via Post Content Image src Attribute PoC, Patch Analysis & Rule

CVE-2026-9620 affects the WP Latest Posts plugin for WordPress versions up to 5.0.11, allowing XSS attacks by authenticated users. Update to the patched version to mitigate this medium severity vulnerability.
June 23, 2026

CVE-2026-9643: WP Meta SEO <= 4.5.18 Unauthenticated Stored Cross-Site Scripting via REQUEST_URI in 404 Logging PoC, Patch Analysis & Rule

CVE-2026-9643 affects the WP Meta SEO plugin (up to v4.5.18) with a CVSS score of 7.2. This high-severity XSS vulnerability allows unauthenticated attackers to inject scripts. Patching is essential to secure your site.
June 23, 2026

CVE-2026-4297: Welcome Software Publishing <= 0.0.31 Authenticated (Subscriber+) Arbitrary Options Update to Privilege Escalation via 'nc.setOption' XML-RPC Method PoC, Patch Analysis & Rule

CVE-2026-4297 affects the Newscred Publishing plugin (up to 0.0.31) with a CVSS score of 8.8. Authenticated attackers can exploit this high-severity vulnerability to escalate privileges. Ensure you update to the patched version.
June 23, 2026

CVE-2026-12094: Advanced Contact Form 7 <= 1.0.0 Missing Authorization to Unauthenticated Arbitrary Contact Form Submission Deletion via 'form_id' Parameter PoC, Patch Analysis & Rule

CVE-2026-12094 affects the Advanced Contact Form 7 Compact Db plugin (v1.0.0) with a medium severity (CVSS 5.3). Unauthenticated attackers can delete contact form submissions; patching is essential to mitigate this risk.
June 23, 2026

CVE-2026-12095: Kargo Takip <= 1.2 Unauthenticated Server-Side Request Forgery via 'api_url' Parameter PoC, Patch Analysis & Rule

CVE-2026-12095 affects the Kargo Takip plugin for WordPress (up to version 1.2) with a CVSS score of 7.2. Unauthenticated SSRF vulnerabilities can expose internal service data; patching is essential for security.
June 23, 2026

CVE-2026-12100: URL Preview <= 1.0 Unauthenticated Server-Side Request Forgery via 'url' Parameter PoC, Patch Analysis & Rule

CVE-2026-12100 affects the Link Preview plugin for WordPress (version 1.0) with a CVSS score of 7.2. Unauthenticated SSRF vulnerabilities can be exploited to access internal services. Patching is essential to mitigate risks.
June 23, 2026

CVE-2026-8896: MIR blocks and shortcodes <= 1.0.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2026-8896 affects the Mir Blocks And Shortcodes plugin (version 1.0.0) with a CVSS score of 6.4. Authenticated users can exploit this medium severity cross-site scripting vulnerability, making patching essential.
June 23, 2026

CVE-2026-11997: Bulk SEO Image <= 1.1 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

CVE-2026-11997 affects the Bulk SEO Image plugin for WordPress (up to version 1.1) with a medium severity (CVSS 4.3) CSRF vulnerability. Unauthenticated attackers can overwrite image ALT-text; ensure you update to the patched version.
June 23, 2026

CVE-2026-9724: MotorDesk <= 1.1.2 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

CVE-2026-9724 affects the Motordesk plugin for WordPress (up to version 1.1.2) with a medium severity (CVSS 4.3) CSRF vulnerability. Unauthenticated attackers can alter plugin settings, making timely patching essential.
June 23, 2026

CVE-2026-9616: Generate Security.txt <= 1.0.12 Missing Authorization to Authenticated (Subscriber+) Security.txt Deletion via delete_securitytxt AJAX Action PoC, Patch Analysis & Rule

CVE-2026-9616 affects the Generate Security.txt plugin for WordPress (up to v1.0.12) with a CVSS score of 4.3. Authenticated users can exploit this medium-severity flaw to delete security.txt or create directories, highlighting the need...
June 23, 2026

CVE-2026-10552: Blue Captcha <= 2.0.1 Cross-Site Request Forgery via 'blcap_action' Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-10552 in Blue Captcha (CVSS 4.3): Blue Captcha. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 23, 2026

CVE-2026-9619: Reviews and Rating <= 1.1.4 Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via sync_reviews AJAX Action PoC, Patch Analysis & Rule

CVE-2026-9619 affects the Reviews And Rating Docplanner plugin for WordPress (up to v1.1.4) with a medium severity (CVSS 4.3). It allows authenticated attackers to bypass authorization, enabling data scraping and misuse of admin email...
June 23, 2026

CVE-2026-8865: Avalon23 Products Filter for WooCommerce <= 1.1.6 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2026-8865 affects the Avalon23 Products Filter for WooCommerce plugin (up to v1.1.6) with a medium severity (CVSS 6.4) Stored XSS vulnerability. Ensure to patch or implement WAF coverage to mitigate potential attacks.
June 23, 2026

CVE-2026-9612: WhatsOrder <= 1.0.1 Unauthenticated Sensitive Information Exposure via Predictable Invoice File URLs PoC, Patch Analysis & Rule

Medium CVE-2026-9612 in Whatsorder Instant Checkout For Woocommerce (CVSS 5.3): WhatsOrder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 23, 2026

CVE-2026-9721: Book a Room Event Calendar <= 1.9 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

CVE-2026-9721 affects the Book A Room Event Calendar plugin for WordPress (up to v1.9) with a CVSS score of 4.3. Unauthenticated attackers can exploit this CSRF vulnerability to alter critical settings. Patching is essential.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works