Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

June 14, 2026

CVE-2026-49770: WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.7.12 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

High CVE-2026-49770 in Wp Travel Engine (CVSS 8.1): WP Travel Engine – Tour Booking Plugin – Tour Operator Software. Atomic Edge summarizes impact, exploitability, and patch details. Update to 6.8.0.
June 14, 2026

CVE-2026-49774: RD Station <= 5.6.0 Authenticated (Contributor+) Remote Code Execution PoC, Patch Analysis & Rule

High CVE-2026-49774 in Integracao Rd Station (CVSS 8.8): RD Station. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.7.2.
June 14, 2026

CVE-2026-49106: Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.6 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

High CVE-2026-49106 in Cf7 Constant Contact (CVSS 8.1): Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.1.7.
June 14, 2026

CVE-2026-49776: GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-49776 in Gptranslate (CVSS 7.5): GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update...
June 14, 2026

CVE-2026-49109: Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

High CVE-2026-49109 in Cf7 Salesforce (CVSS 8.1): Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.4.4.
June 14, 2026

CVE-2026-49765: Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

High CVE-2026-49765 in Cf7 Mailchimp (CVSS 8.1): Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.1.9.
June 14, 2026

CVE-2026-49113: Cornerstone < 7.8.8 Authenticated (Subscriber+) Arbitrary Code Execution PoC, Patch Analysis & Rule

High CVE-2026-49113 in Cornerstone (CVSS 8.8): Cornerstone < 7.8.8 - Authenticated (Subscriber+) Arbitrary Code Execution. Atomic Edge summarizes impact, exploitability, and patch details.
June 14, 2026

CVE-2026-49110: Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups. <= 3.1.4 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-49110 in Upsell Order Bump Offer For Woocommerce (CVSS 5.3): Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently.... Atomic Edge summarizes impact, exploitability, and patch...
June 14, 2026

CVE-2026-49781: OttoKit: All-in-One Automation Platform <= 1.1.27 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule

High CVE-2026-49781 in Suretriggers (CVSS 8.1): OttoKit: All-in-One Automation Platform. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.1.28.
June 13, 2026

CVE-2026-10580: Hippoo Mobile App for WooCommerce <= 1.9.4 Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API PoC, Patch Analysis & Rule

Critical CVE-2026-10580 in Hippoo (CVSS 9.8): Hippoo Mobile App for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.9.5.
June 13, 2026

CVE-2026-5411: WP Captcha PRO <= 5.38 Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload PoC, Patch Analysis & Rule

High CVE-2026-5411 in Advanced Google Recaptcha (CVSS 8.8): WP Captcha PRO. Atomic Edge summarizes impact, exploitability, and patch details.
June 13, 2026

CVE-2026-8608: Event Monster <= 2.1.0 Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action PoC, Patch Analysis & Rule

Medium CVE-2026-8608 in Event Monster (CVSS 5.3): Event Monster. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.1.
June 13, 2026

CVE-2026-49078: WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.7.10 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-49078 in Wp Travel Engine (CVSS 5.3): WP Travel Engine – Tour Booking Plugin – Tour Operator Software. Atomic Edge summarizes impact, exploitability, and patch details. Update to 6.7.11.
June 13, 2026

CVE-2026-7654: Admin Columns <= 7.0.18 Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta Value PoC, Patch Analysis & Rule

High CVE-2026-7654 in Codepress Admin Columns (CVSS 8.8): Admin Columns. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 13, 2026

CVE-2019-25738: Hybrid Composer <= 1.4.6 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2019-25738 in Hybrid Composer (CVSS 5.3): Hybrid Composer. Atomic Edge summarizes impact, exploitability, and patch details.
June 13, 2026

CVE-2026-9290: WP User Manager <= 2.9.17 Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter PoC, Patch Analysis & Rule

High CVE-2026-9290 in Wp User Manager (CVSS 7.5): WP User Manager. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.9.18.
June 13, 2026

CVE-2026-49082: Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule

Medium CVE-2026-49082 in Chatway Live Chat (CVSS 4.3): Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.4.9.
June 13, 2026

CVE-2026-8385: WP Go Maps < 10.0.10 Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback PoC, Patch Analysis & Rule

Medium CVE-2026-8385 in Wp Google Maps (CVSS 5.3): WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
June 13, 2026

CVE-2026-49083: LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.5.1 Authenticated (Contributor+) Privilege Escalation PoC, Patch Analysis & Rule

High CVE-2026-49083 in Latepoint (CVSS 8.8): LatePoint – Calendar Booking Plugin for Appointments and Events. Atomic Edge summarizes impact, exploitability, and patch details. Update to 5.5.2.
June 13, 2026

CVE-2026-49079: JetSearch <= 3.5.17 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-49079 in Jet Search (CVSS 7.5): JetSearch. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works