Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

2026-02-18

CVE-2026-1461: Simple Membership <= 4.7.0 – Unauthenticated Improper Handling of Missing Values (simple-membership)

The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, and including, 4.7.0 via the Stripe webhook handler. This is due to the plugin only validating webhook signatures when the stripe-webhook-signing-secret setting is configured, which is empty by default. This makes it possible for unauthenticated attackers…
2026-02-18

CVE-2025-13079: Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.4.2 – Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens (popup-builder)

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.2. This is due to the plugin generating predictable unsubscribe tokens using deterministic data. This makes it possible for unauthenticated attackers to unsubscribe arbitrary subscribers from mailing lists via…
2026-02-18

CVE-2025-12707: Library Management System <= 3.2.1 – Unauthenticated SQL Injection (library-management-system)

The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries…
2026-02-18

CVE-2026-25375: Image Photo Gallery Final Tiles Grid <= 3.6.10 – Missing Authorization (final-tiles-grid-gallery-lite)

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.6.10. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
2026-02-18

CVE-2025-14294: Razorpay for WooCommerce <= 4.7.8 – Missing Authentication to Unauthenticated Order Modification (woo-razorpay)

The Razorpay for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the getCouponList() function in all versions up to, and including, 4.7.8. This is due to the checkAuthCredentials() permission callback always returning true, providing no actual authentication. This makes it possible for unauthenticated attackers to…
2026-02-18

CVE-2025-14864: Virusdie <= 1.1.7 – Missing Authorization to Authenticated (Subscriber+) API Key Disclosure (virusdie)

The Virusdie - One-click website security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.7. This is due to missing capability checks on the `vd_get_apikey` function which is hooked to `wp_ajax_virusdie_apikey`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve the site's…
2026-02-18

CVE-2026-23549: WpEvently <= 5.1.1 – Unauthenticated PHP Object Injection (mage-eventpress)

The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.1.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin…
2026-02-18

CVE-2026-23541: Mail Mint <= 1.19.4 – Missing Authorization (mail-mint)

The Mail Mint plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.19.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-02-18

CVE-2026-1581: wpForo Forum <= 2.4.14 – Unauthenticated Time-Based SQL Injection (wpforo)

The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries…
2026-02-18

CVE-2025-13732: s2Member <= 251005 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode (s2member)

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's2Eot' shortcode in all versions up to, and including, 251005 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works