
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
June 21, 2026
CVE-2026-48880: WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.2 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-48880 in Wp Job Portal (CVSS 6.4): WP Job Portal – AI-Powered Recruitment System for Company or Job Board website. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.5.3.
June 21, 2026
CVE-2026-48965: Backup, Restore and Migrate your sites with XCloner <= 4.8.6 Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2026-48965 in Xcloner Backup And Restore (CVSS 4.3): Backup, Restore and Migrate your sites with XCloner. Atomic Edge summarizes impact, exploitability, and patch details. Update to 4.8.7.
June 21, 2026
CVE-2026-48889: Booking for Appointments and Events Calendar – Amelia <= 2.3 Authenticated (Subscriber+) Privilege Escalation PoC, Patch Analysis & Rule
High CVE-2026-48889 in Ameliabooking (CVSS 8.8): Booking for Appointments and Events Calendar – Amelia. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.4.
June 21, 2026
CVE-2025-12352: Gravity Forms <= 2.9.20 Unauthenticated Arbitrary File Upload via 'copy_post_image' PoC, Patch Analysis & Rule
Critical CVE-2025-12352 in Gravityforms (CVSS 9.8): Gravity Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 20, 2026
CVE-2026-5305: Email Encoder < 0.3.12 (premium) < 1.0.25 (free) Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2026-5305 in Email Address Encoder (CVSS 7.2): Email Encoder < 0.3.12 (premium) < 1.0.25 (free) - Unauthenticated Stored Cross-Site Scripting. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.0.25.
June 20, 2026
CVE-2026-9690: Media folder Addon <= 4.0.1 Unauthenticated Arbitrary File Download PoC, Patch Analysis & Rule
Critical CVE-2026-9690 in Wp Media Folder Addon (CVSS 9.1): Media folder Addon. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 20, 2026
CVE-2026-49107: Thrive Apprentice < 10.8.10.2 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-49107 in Thrive Apprentice (CVSS 8.1): Thrive Apprentice < 10.8.10.2 - Unauthenticated PHP Object Injection. Atomic Edge summarizes impact, exploitability, and patch details.
June 20, 2026
CVE-2026-5305: Email Encoder < 0.3.12 (premium) < 1.0.25 (free) Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2026-5305 in Email Encoder Premium (CVSS 7.2): Email Encoder < 0.3.12 (premium) < 1.0.25 (free) - Unauthenticated Stored Cross-Site Scripting. Atomic Edge summarizes impact, exploitability, and patch details.
June 20, 2026
CVE-2026-10737: SP Project & Document Manager <= 4.71 Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function PoC, Patch Analysis & Rule
High CVE-2026-10737 in Sp Client Document Manager (CVSS 7.5): SP Project & Document Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 14, 2026
CVE-2026-10586: Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 Authenticated (Author+) Server-Side Request Forgery PoC, Patch Analysis & Rule
High CVE-2026-10586 in Essential Blocks (CVSS 7.2): Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns. Atomic Edge summarizes impact, exploitability, and patch details. Update to 6.1.4.
June 14, 2026
CVE-2026-49768: Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms <= 1.26.13 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-49768 in Happyforms (CVSS 8.1): Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments &.... Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.26.14.
June 14, 2026
CVE-2026-49769: wpForo Forum <= 3.1.0 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-49769 in Wpforo (CVSS 8.1): wpForo Forum. Atomic Edge summarizes impact, exploitability, and patch details. Update to 3.1.1.
June 14, 2026
CVE-2026-49767: wpForo Forum <= 3.1.0 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-49767 in Wpforo (CVSS 5.3): wpForo Forum. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.1.1.
June 14, 2026
CVE-2026-49763: Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.3.7 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-49763 in Cf7 Hubspot (CVSS 8.1): Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.3.8.
June 14, 2026
CVE-2026-49778: WPFunnels Pro <= 2.9.4 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2026-49778 in Wpfunnels Pro (CVSS 7.2): WPFunnels Pro. Atomic Edge summarizes impact, exploitability, and patch details.
June 14, 2026
CVE-2026-49764: RegistrationMagic – User Registration Forms Plugin <= 6.0.8.6 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-49764 in Custom Registration Form Builder With Submission Manager (CVSS 5.3): RegistrationMagic – User Registration Forms Plugin. Atomic Edge summarizes impact, exploitability, and patch details. Update to 6.0.8.7.
June 14, 2026
CVE-2026-49773: FV Flowplayer Video Player < 7.5.51.7212 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-49773 in Fv Wordpress Flowplayer (CVSS 6.4): FV Flowplayer Video Player < 7.5.51.7212 - Authenticated (Subscriber+) Stored Cross-Site Scripting. Atomic Edge summarizes impact, exploitability, and patch details.
June 14, 2026
CVE-2026-49775: Welcart e-Commerce <= 2.11.28 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-49775 in Usc E Shop (CVSS 5.3): Welcart e-Commerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.11.29.
June 14, 2026
CVE-2026-49771: Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.41 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2026-49771 in Photo Gallery (CVSS 6.5): Photo Gallery by 10Web – Mobile-Friendly Image Gallery. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.8.42.
June 14, 2026
CVE-2026-49077: Wp EMember <= v10.2.2 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2026-49077 in Wp EMember (CVSS 5.3): Wp EMember. Atomic Edge summarizes impact, exploitability, and patch details.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
