
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
June 13, 2026
CVE-2026-49766: WP User Manager – User Profile Builder & Membership <= 2.9.16 Authenticated (Subscriber+) Arbitrary File Deletion PoC, Patch Analysis & Rule
High CVE-2026-49766 in Wp User Manager (CVSS 8.1): WP User Manager – User Profile Builder & Membership. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.9.17.
June 13, 2026
CVE-2026-9016: Debug Log Manager <= 2.5.0 Unauthenticated Improper Output Neutralization for Logs via log_js_errors AJAX Action PoC, Patch Analysis & Rule
Medium CVE-2026-9016 in Debug Log Manager (CVSS 5.3): Debug Log Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.5.1.
June 13, 2026
CVE-2026-49105: WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-49105 in Cf7 Zendesk (CVSS 8.1): WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.1.5.
June 13, 2026
CVE-2026-49104: Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-49104 in Cf7 Infusionsoft (CVSS 8.1): Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
June 13, 2026
CVE-2026-9691: Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-9691 in Cf7 Active Campaign (CVSS 8.1): Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.1.2.
June 13, 2026
CVE-2026-49112: Shared Files – Frontend File Upload Form & Secure File Sharing <= 1.7.64 Unauthenticated Path Traversal PoC, Patch Analysis & Rule
Medium CVE-2026-49112 in Shared Files (CVSS 5.3): Shared Files – Frontend File Upload Form & Secure File Sharing. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.7.65.
June 13, 2026
CVE-2019-25727: 10WebAdManager <= 1.0.11 Unauthenticated Arbitrary File Download PoC, Patch Analysis & Rule
Medium CVE-2019-25727 in Ad Manager Wd (CVSS 5.3): 10WebAdManager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 13, 2026
CVE-2026-49081: User Registration Stripe <= 1.3.12 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-49081 in User Registration Stripe (CVSS 5.3): User Registration Stripe. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 13, 2026
CVE-2026-49085: WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-49085 in Cf7 Insightly (CVSS 8.1): WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.1.5.
June 12, 2026
CVE-2025-12656: Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 Authenticated (Admin+) Arbitrary Directory Deletion PoC, Patch Analysis & Rule
Low CVE-2025-12656 in Wpvivid Backuprestore (CVSS 3.8): Migration, Backup, Staging – WPvivid Backup & Migration. Atomic Edge summarizes impact, exploitability, and patch details. Update to 0.9.129.
June 12, 2026
CVE-2026-9719: LatePoint <= 5.6.0 Cross-Site Request Forgery via invoices__change_status Action PoC, Patch Analysis & Rule
Medium CVE-2026-9719 in Latepoint (CVSS 4.3): LatePoint. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.6.1.
June 12, 2026
CVE-2026-8976: RSS Aggregator by Feedzy <= 5.1.7 Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions PoC, Patch Analysis & Rule
Medium CVE-2026-8976 in Feedzy Rss Feeds (CVSS 4.3): RSS Aggregator by Feedzy. Atomic Edge summarizes impact, exploitability, and patch details. Update to 5.1.8.
June 12, 2026
CVE-2026-8438: All-In-One Security (AIOS) <= 5.4.7 Unauthenticated Stored Cross-Site Scripting via REST API Request Path PoC, Patch Analysis & Rule
High CVE-2026-8438 in All In One Wp Security And Firewall (CVSS 7.2): All-In-One Security (AIOS). Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.4.8.
June 12, 2026
CVE-2026-8893: Express Payment For Stripe <= 1.28.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
Medium CVE-2026-8893 in Wp Stripe Express (CVSS 6.4): Express Payment For Stripe. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.28.2.
June 12, 2026
CVE-2026-7047: Frontend User Notes <= 2.1.1 Cross-Site Request Forgery to Note Content Modification via 'confirmEdit' Action PoC, Patch Analysis & Rule
Medium CVE-2026-7047 in Frontend User Notes (CVSS 4.3): Frontend User Notes. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.2.0.
June 12, 2026
CVE-2026-10038: Charitable <= 1.8.11.1 Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-10038 in Charitable (CVSS 4.3): Charitable. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.8.11.2.
June 12, 2026
CVE-2026-8900: Simple SEO Slideshow <= 1.2.8 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
Medium CVE-2026-8900 in Simple Seo Slideshow (CVSS 6.4): Simple SEO Slideshow. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 12, 2026
CVE-2026-7523: Alba Board <= 2.1.3 Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'card_id' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-7523 in Alba Board (CVSS 4.3): Alba Board. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.4.
June 12, 2026
CVE-2026-5415: WP Captcha PRO <= 5.38 Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link PoC, Patch Analysis & Rule
High CVE-2026-5415 in Advanced Google Recaptcha (CVSS 8.8): WP Captcha PRO. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 12, 2026
CVE-2026-8206: Kirki 6.0.0 6.0.6 Unauthenticated Privilege Escalation via ‘handle_forgot_password’ PoC, Patch Analysis & Rule
Critical CVE-2026-8206 in Kirki (CVSS 9.8): Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 6.0.7.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
