Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

August 15, 2026

CVE-2026-10734: Infility Global <= 2.15.21 Unauthenticated Stored Cross-Site Scripting via /cf7_record Log Endpoint PoC, Patch Analysis & Rule

CVE-2026-10734 affects the Infility Global plugin for WordPress (up to 2.15.21) with a high severity CVSS score of 7.2. Unauthenticated attackers can exploit stored XSS via the /cf7_record log endpoint. Update to the patched version.
August 15, 2026

CVE-2024-13784: Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

CVE-2024-13784 affects the Arforms Form Builder plugin (up to v1.8.5) with a critical CVSS score of 9.8. Unauthenticated PHP Object Injection can lead to severe impacts if combined with vulnerable themes or plugins. Patching is essential.
August 15, 2026

CVE-2026-18347: Kirki <= 6.1.1 Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'context' Parameter PoC, Patch Analysis & Rule

CVE-2026-18347 affects the Kirki plugin for WordPress (up to 6.1.1) with a medium severity (CVSS 4.3) authentication bypass. Update to version 6.2.0 to mitigate risks of unauthorized access to sensitive user data.
August 15, 2026

CVE-2026-17604: Kirki <= 6.1.1 Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter PoC, Patch Analysis & Rule

CVE-2026-17604 affects the Kirki plugin (up to version 6.1.1) with a medium severity (CVSS 4.9) file upload vulnerability. Update to version 6.2.0 to mitigate risks of unauthorized file access by authenticated users.
August 15, 2026

CVE-2026-12998: Forminator Forms <= 1.55.0.2 Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter PoC, Patch Analysis & Rule

CVE-2026-12998 affects the Forminator plugin for WordPress (up to version 1.55.0.2) with a medium severity (CVSS 5.3). Unauthenticated attackers can access sensitive draft data; update to version 1.55.1 to mitigate.
August 15, 2026

CVE-2026-13424: Online Scheduling and Appointment Booking System <= 27.7 Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action PoC, Patch Analysis & Rule

CVE-2026-13424 affects the Bookly Responsive Appointment Booking Tool (up to version 27.7) with a high severity CVSS score of 7.2. Ensure you update to version 28.0 to mitigate the stored XSS risk.
August 15, 2026

CVE-2026-17581: WCPOS <= 1.9.14 Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine PoC, Patch Analysis & Rule

CVE-2026-17581 affects the Woocommerce Pos plugin (up to 1.9.14) with a CVSS score of 7.2. Authenticated attackers can exploit this high-severity remote code execution vulnerability. Upgrade to version 1.9.15 to mitigate risks.
August 15, 2026

CVE-2026-17608: WP Compress <= 7.10.09 Cross-Site Request Forgery to Arbitrary Options Deletion PoC, Patch Analysis & Rule

CVE-2026-17608 affects the WP Compress Image Optimizer plugin (up to v7.10.09) with a medium severity CVSS of 6.5. Unauthenticated attackers can exploit CSRF to delete critical WordPress options. Update to v7.20.01 to mitigate.
August 15, 2026

CVE-2026-2497: Gallery by BestWebSoft <= 4.7.9 Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys PoC, Patch Analysis & Rule

CVE-2026-2497 affects the Gallery Plugin for WordPress (up to version 4.7.9) with a CVSS score of 7.2. Authenticated attackers can exploit SQL injection vulnerabilities; update to version 4.8.0 to mitigate risks.
August 15, 2026

CVE-2026-17087: WP Travel Engine <= 6.8.4 Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter PoC, Patch Analysis & Rule

CVE-2026-17087 affects WP Travel Engine versions up to 6.8.4, allowing unauthorized access to sensitive booking details. Upgrade to 6.8.5 to mitigate this high-severity CSRF vulnerability.
August 15, 2026

CVE-2026-2283: User Login History <= 2.1.7 Authenticated (Administrator+) SQL Injection via 'blog_id' Parameter PoC, Patch Analysis & Rule

CVE-2026-2283 affects the User Login History plugin for WordPress (up to v2.1.7) with a medium severity SQL injection vulnerability. Update to v2.1.8 to mitigate risks from authenticated attackers on multisite installations.
August 15, 2026

CVE-2026-15351: WC Vendors <= 2.7.0 Authenticated (Shop Manager+) SQL Injection via 'status' Parameter PoC, Patch Analysis & Rule

CVE-2026-15351 affects the WC Vendors plugin (up to v2.7.0) with a medium severity (CVSS 4.9) SQL injection vulnerability. Users should upgrade to v2.7.1 to mitigate risks of data exposure.
August 15, 2026

CVE-2026-10035: Turnkey bbPress by WeaverTheme <= 1.7.1 Authenticated (Administrator+) PHP Object Injection PoC, Patch Analysis & Rule

CVE-2026-10035 affects the Weaver For Bbpress plugin (up to 1.7.1) with a medium severity (CVSS 6.6) PHP Object Injection vulnerability. Administrators should upgrade to version 1.8 to mitigate potential risks.
August 15, 2026

CVE-2026-15790: Video Gallery <= 4.0.4 Authenticated (Author+) Stored Cross-Site Scripting via Attachment 'post_title' via emd_mb_meta Shortcode PoC, Patch Analysis & Rule

CVE-2026-15790 affects the Youtube Showcase plugin for WordPress (up to 4.0.4) with a medium severity XSS vulnerability. Users should update to version 4.0.5 to mitigate risks from potential script injections.
August 15, 2026

CVE-2026-9767: The School Management <= 5.4 Authenticated (Custom+) SQL Injection via 'order[0][dir]' Parameter PoC, Patch Analysis & Rule

CVE-2026-9767 affects the School Management System plugin for WordPress (up to v5.4) with a medium severity (CVSS 6.5) SQL injection vulnerability. Users should upgrade to v5.5 to mitigate risks of data exposure.
August 15, 2026

CVE-2026-18402: SureDash <= 1.10.3 Authenticated (Contributor+) Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-18402 affects SureDash plugin versions up to 1.10.3 with a medium severity CVSS score of 6.4. Authenticated attackers can exploit stored XSS vulnerabilities; update to version 1.10.4 for protection.
August 15, 2026

CVE-2026-15604: Toocheke Companion <= 2.10 Authenticated (Contributor+) Stored Cross-Site Scripting via 'series_bg_color' Post Meta PoC, Patch Analysis & Rule

CVE-2026-15604 affects the Toocheke Companion plugin (up to v2.10) with a medium severity CVSS score of 6.4. Update to v2.11 to mitigate Stored XSS risks that allow authenticated users to inject scripts in the admin dashboard.
August 15, 2026

CVE-2026-16775: Smash Balloon Social Post Feed <= 4.9.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-16775 affects the Custom Facebook Feed plugin (up to v4.9.0) with a medium severity (CVSS 6.4) Stored XSS vulnerability. Users should upgrade to v4.10.0 to mitigate risks from authenticated attackers.
August 15, 2026

CVE-2026-16758: Snippet Shortcodes <= 5.2.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2026-16758 affects the Shortcode Variables plugin for WordPress (up to version 5.2.0) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability, highlighting the need for immediate patching.
August 15, 2026

CVE-2026-17582: Slider Hero with Video Background, Animation <= 9.1.7 Authenticated (Administrator+) SQL Injection via 'description' Slide Field (Second-Order via Duplicate) PoC, Patch Analysis & Rule

CVE-2026-17582 affects the Slider Hero plugin for WordPress (up to v9.1.7) with a medium severity score of 4.9. Authenticated admins can exploit a SQL injection vulnerability. Upgrade to v9.1.8 to mitigate risks.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works