Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

June 21, 2026

CVE-2026-48880: WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.2 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2026-48880 in Wp Job Portal (CVSS 6.4): WP Job Portal – AI-Powered Recruitment System for Company or Job Board website. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.5.3.
June 21, 2026

CVE-2026-48965: Backup, Restore and Migrate your sites with XCloner <= 4.8.6 Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule

Medium CVE-2026-48965 in Xcloner Backup And Restore (CVSS 4.3): Backup, Restore and Migrate your sites with XCloner. Atomic Edge summarizes impact, exploitability, and patch details. Update to 4.8.7.
June 21, 2026

CVE-2026-48889: Booking for Appointments and Events Calendar – Amelia <= 2.3 Authenticated (Subscriber+) Privilege Escalation PoC, Patch Analysis & Rule

High CVE-2026-48889 in Ameliabooking (CVSS 8.8): Booking for Appointments and Events Calendar – Amelia. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.4.
June 21, 2026

CVE-2025-12352: Gravity Forms <= 2.9.20 Unauthenticated Arbitrary File Upload via 'copy_post_image' PoC, Patch Analysis & Rule

Critical CVE-2025-12352 in Gravityforms (CVSS 9.8): Gravity Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 20, 2026

CVE-2026-5305: Email Encoder < 0.3.12 (premium) < 1.0.25 (free) Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

High CVE-2026-5305 in Email Address Encoder (CVSS 7.2): Email Encoder < 0.3.12 (premium) < 1.0.25 (free) - Unauthenticated Stored Cross-Site Scripting. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.0.25.
June 20, 2026

CVE-2026-9690: Media folder Addon <= 4.0.1 Unauthenticated Arbitrary File Download PoC, Patch Analysis & Rule

Critical CVE-2026-9690 in Wp Media Folder Addon (CVSS 9.1): Media folder Addon. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 20, 2026

CVE-2026-49107: Thrive Apprentice < 10.8.10.2 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

High CVE-2026-49107 in Thrive Apprentice (CVSS 8.1): Thrive Apprentice < 10.8.10.2 - Unauthenticated PHP Object Injection. Atomic Edge summarizes impact, exploitability, and patch details.
June 20, 2026

CVE-2026-5305: Email Encoder < 0.3.12 (premium) < 1.0.25 (free) Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

High CVE-2026-5305 in Email Encoder Premium (CVSS 7.2): Email Encoder < 0.3.12 (premium) < 1.0.25 (free) - Unauthenticated Stored Cross-Site Scripting. Atomic Edge summarizes impact, exploitability, and patch details.
June 20, 2026

CVE-2026-10737: SP Project & Document Manager <= 4.71 Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function PoC, Patch Analysis & Rule

High CVE-2026-10737 in Sp Client Document Manager (CVSS 7.5): SP Project & Document Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 14, 2026

CVE-2026-10586: Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 Authenticated (Author+) Server-Side Request Forgery PoC, Patch Analysis & Rule

High CVE-2026-10586 in Essential Blocks (CVSS 7.2): Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns. Atomic Edge summarizes impact, exploitability, and patch details. Update to 6.1.4.
June 14, 2026

CVE-2026-49768: Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms <= 1.26.13 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

High CVE-2026-49768 in Happyforms (CVSS 8.1): Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments &.... Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.26.14.
June 14, 2026

CVE-2026-49769: wpForo Forum <= 3.1.0 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

High CVE-2026-49769 in Wpforo (CVSS 8.1): wpForo Forum. Atomic Edge summarizes impact, exploitability, and patch details. Update to 3.1.1.
June 14, 2026

CVE-2026-49767: wpForo Forum <= 3.1.0 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-49767 in Wpforo (CVSS 5.3): wpForo Forum. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.1.1.
June 14, 2026

CVE-2026-49763: Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.3.7 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

High CVE-2026-49763 in Cf7 Hubspot (CVSS 8.1): Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.3.8.
June 14, 2026

CVE-2026-49778: WPFunnels Pro <= 2.9.4 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

High CVE-2026-49778 in Wpfunnels Pro (CVSS 7.2): WPFunnels Pro. Atomic Edge summarizes impact, exploitability, and patch details.
June 14, 2026

CVE-2026-49764: RegistrationMagic – User Registration Forms Plugin <= 6.0.8.6 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-49764 in Custom Registration Form Builder With Submission Manager (CVSS 5.3): RegistrationMagic – User Registration Forms Plugin. Atomic Edge summarizes impact, exploitability, and patch details. Update to 6.0.8.7.
June 14, 2026

CVE-2026-49773: FV Flowplayer Video Player < 7.5.51.7212 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2026-49773 in Fv Wordpress Flowplayer (CVSS 6.4): FV Flowplayer Video Player < 7.5.51.7212 - Authenticated (Subscriber+) Stored Cross-Site Scripting. Atomic Edge summarizes impact, exploitability, and patch details.
June 14, 2026

CVE-2026-49775: Welcart e-Commerce <= 2.11.28 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-49775 in Usc E Shop (CVSS 5.3): Welcart e-Commerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.11.29.
June 14, 2026

CVE-2026-49771: Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.41 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule

Medium CVE-2026-49771 in Photo Gallery (CVSS 6.5): Photo Gallery by 10Web – Mobile-Friendly Image Gallery. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.8.42.
June 14, 2026

CVE-2026-49077: Wp EMember <= v10.2.2 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

Medium CVE-2026-49077 in Wp EMember (CVSS 5.3): Wp EMember. Atomic Edge summarizes impact, exploitability, and patch details.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works