Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

June 23, 2026

CVE-2026-8628: EntreDroppers <= 1.1.2 Reflected Cross-Site Scripting via PHP_SELF Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-8628 in Entredropper (CVSS 6.1): EntreDroppers. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 23, 2026

CVE-2026-9175: Devs Accounting <= 1.2.0 Missing Authorization to Unauthenticated Sensitive Information Exposure via 'id' Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-9175 in Devs Accounting (CVSS 5.3): Devs Accounting. Atomic Edge summarizes impact, exploitability, and patch details.
June 23, 2026

CVE-2026-9172: Devs Accounting <= 1.2.0 Missing Authorization to Unauthenticated Account Deletion via /delete-account/ REST Endpoint PoC, Patch Analysis & Rule

Medium CVE-2026-9172 in Devs Accounting (CVSS 5.3): Devs Accounting. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 23, 2026

CVE-2026-8622: Image Sizes on Demand <= 1.3 Reflected Cross-Site Scripting via PHP_SELF Server Variable PoC, Patch Analysis & Rule

Medium CVE-2026-8622 in Image Sizes On Demand (CVSS 6.1): Image Sizes on Demand. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 22, 2026

CVE-2026-48886: JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-48886 in Js Support Ticket (CVSS 7.5): JS Help Desk – AI-Powered Support & Ticketing System. Atomic Edge summarizes impact, exploitability, and patch details. Update to 3.1.0.
June 22, 2026

CVE-2026-48875: JetSmartFilters <= 3.8.1 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-48875 in Jet Smart Filters (CVSS 7.5): JetSmartFilters. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 22, 2026

CVE-2026-48868: Simple Shopping Cart <= 5.2.9 Unauthenticated Insecure Direct Object Reference PoC, Patch Analysis & Rule

Medium CVE-2026-48868 in Wordpress Simple Paypal Shopping Cart (CVSS 5.3): Simple Shopping Cart. Atomic Edge summarizes impact, exploitability, and patch details. Update to 5.3.0.
June 22, 2026

CVE-2026-48874: GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.8.7 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule

Medium CVE-2026-48874 in Gamipress (CVSS 6.5): GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage...
June 22, 2026

CVE-2026-48870: King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder <= 51.1.62 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2026-48870 in King Addons (CVSS 6.4): King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega.... Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
June 22, 2026

CVE-2026-48881: TrueBooker – Appointment Booking and Scheduler System <= 1.1.9 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-48881 in Truebooker Appointment Booking (CVSS 5.3): TrueBooker – Appointment Booking and Scheduler System. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.2.0.
June 22, 2026

CVE-2026-48885: HollerBox — Fast & Effective Popups & Lead-Generation <= 2.3.10.1 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

High CVE-2026-48885 in Holler Box (CVSS 7.2): HollerBox — Fast & Effective Popups & Lead-Generation. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.3.11.
June 22, 2026

CVE-2026-28116: Progress Planner <= 1.9.0 Authenticated (Editor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2026-28116 in Progress Planner (CVSS 4.4): Progress Planner. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.9.1.
June 22, 2026

CVE-2026-27351: Employee, Leave and Recruitment Management System – Crew HRM <= 1.2.2 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-27351 in Hr Management (CVSS 4.3): Employee, Leave and Recruitment Management System – Crew HRM. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.2.3.
June 22, 2026

CVE-2026-9599: Tectite Forms <= 1.3 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

Medium CVE-2026-9599 in Tectite Forms (CVSS 4.3): Tectite Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 22, 2026

CVE-2026-48873: Montonio for WooCommerce <= 10.1.2 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-48873 in Montonio For Woocommerce (CVSS 5.3): Montonio for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details. Update to 10.1.3.
June 22, 2026

CVE-2026-9234: JTL-Connector for WooCommerce <= 2.4.1 Missing Authorization to Authenticated (Subscriber+) Settings Modification via Multiple Functions PoC, Patch Analysis & Rule

Medium CVE-2026-9234 in Woo Jtl Connector (CVSS 4.3): JTL-Connector for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.4.2.
June 22, 2026

CVE-2026-8422: Remove meta boxes per user role <= 1.01 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule

Medium CVE-2026-8422 in Remove Meta Boxes Per User Role (CVSS 4.3): Remove meta boxes per user role. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 22, 2026

CVE-2026-9050: Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Deactivation PoC, Patch Analysis & Rule

Medium CVE-2026-9050 in Revslider (CVSS 4.3): Slider Revolution 6.0.0-6.7.55 and 7.0.0-7.0.14 - Missing Authorization to Authenticated.... Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 22, 2026

CVE-2026-27395: Support Board < 3.8.9 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule

Critical CVE-2026-27395 in Supportboard (CVSS 9.8): Support Board < 3.8.9 - Unauthenticated Privilege Escalation. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 22, 2026

CVE-2026-3722: Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) <= 4.9 Authenticated (Author+) Stored Cross-Site Scripting via Image Attribute PoC, Patch Analysis & Rule

Medium CVE-2026-3722 in Auto Image Attributes From Filename With Bulk Updater (CVSS 6.4): Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO). Atomic Edge summarizes impact, exploitability...
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works