
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
June 22, 2026
CVE-2026-48865: LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.6 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-48865 in Learnpress (CVSS 6.1): LearnPress – WordPress LMS Plugin for Create and Sell Online Courses. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.3.7.
June 22, 2026
CVE-2026-9048: Slider Revolution 7.0.0 7.0.14 Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2026-9048 in Revslider (CVSS 4.3): Slider Revolution 7.0.0 - 7.0.14 - Incorrect Authorization to Authenticated (Contributor+) Sensitive.... Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 22, 2026
CVE-2026-42762: VikBooking Hotel Booking Engine & PMS <= 1.8.9 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2026-42762 in Vikbooking (CVSS 7.2): VikBooking Hotel Booking Engine & PMS. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.8.10.
June 21, 2026
CVE-2026-48967: Geo Mashup <= 1.13.19 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2026-48967 in Geo Mashup (CVSS 6.5): Geo Mashup. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.13.20.
June 21, 2026
CVE-2026-8653: MasterStudy LMS Pro Plus <= 4.8.20 Authenticated (Instructor+) SQL Injection via 'columns' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-8653 in Masterstudy Lms Learning Management System Pro (CVSS 6.5): MasterStudy LMS Pro Plus. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 21, 2026
CVE-2026-49055: Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2026-49055 in Drag And Drop Multiple File Upload Contact Form 7 (CVSS 7.2): Drag and Drop Multiple File Upload for Contact Form 7. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update...
June 21, 2026
CVE-2026-49057: JobSearch WP Job Board <= 3.2.7 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-49057 in Wp Jobsearch (CVSS 5.3): JobSearch WP Job Board. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 21, 2026
CVE-2026-49780: Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.2 Authenticated (Customer+) Privilege Escalation PoC, Patch Analysis & Rule
High CVE-2026-49780 in Dokan Lite (CVSS 8.8): Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
June 21, 2026
CVE-2026-48867: Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker <= 11.1.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2026-48867 in Quiz Master Next (CVSS 7.2): Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker. Atomic Edge summarizes impact, exploitability, and patch details. Update to 11.1.3.
June 21, 2026
CVE-2026-34892: Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-34892 in Seo By Rank Math (CVSS 4.3): Rank Math SEO – AI SEO Tools to Dominate SEO Rankings. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.0.271.1.
June 21, 2026
CVE-2026-42775: AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.7.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2026-42775 in Automatorwp (CVSS 7.2): AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
June 21, 2026
CVE-2026-48969: Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.9 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-48969 in Really Simple Ssl (CVSS 4.3): Really Simple Security – Simple and Performant Security (formerly Really Simple SSL). Atomic Edge summarizes impact, exploitability, and patch details. Update to 9.5.10.
June 21, 2026
CVE-2026-48970: Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) <= 9.5.10 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-48970 in Really Simple Ssl (CVSS 5.3): Really Simple Security – Simple and Performant Security (formerly Really Simple SSL). Atomic Edge summarizes impact, exploitability, and patch details. Update to 9.5.10.1.
June 21, 2026
CVE-2026-48966: FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2026-48966 in Funnel Builder (CVSS 7.2): FunnelKit – Funnel Builder for WooCommerce Checkout. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.15.0.3.
June 21, 2026
CVE-2026-48882: WP Time Slots Booking Form <= 1.2.50 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2026-48882 in Wp Time Slots Booking Form (CVSS 6.5): WP Time Slots Booking Form. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.2.51.
June 21, 2026
CVE-2026-49056: WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.4 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2026-49056 in Print Invoices Packing Slip Labels For Woocommerce (CVSS 5.3): WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels. Atomic Edge summarizes impact, exploitability, and patch...
June 21, 2026
CVE-2026-48878: Visual Link Preview <= 2.4.1 Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2026-48878 in Visual Link Preview (CVSS 4.3): Visual Link Preview. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.4.2.
June 21, 2026
CVE-2026-48887: JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-48887 in Js Support Ticket (CVSS 5.3): JS Help Desk – AI-Powered Support & Ticketing System. Atomic Edge summarizes impact, exploitability, and patch details. Update to 3.1.0.
June 21, 2026
CVE-2026-48964: ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2026-48964 in Elex Helpdesk Customer Support Ticket System (CVSS 6.5): ELEX WordPress HelpDesk & Customer Ticketing System. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to...
June 21, 2026
CVE-2026-49782: Elementor Website Builder – more than just a page builder <= 4.1.0 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-49782 in Elementor (CVSS 4.3): Elementor Website Builder – more than just a page builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.1.1.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
