Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

August 14, 2026

CVE-2026-18855: Link Library <= 7.9.4 Unauthenticated Arbitrary File Deletion via link_url Parameter PoC, Patch Analysis & Rule

CVE-2026-18855 affects the Link Library plugin for WordPress (up to 7.9.4) with a critical CVSS score of 9.1. It allows unauthenticated file deletion, risking remote code execution. Update to version 7.9.5 to mitigate this issue.
August 14, 2026

CVE-2026-15142: Real Estate Manager Pro <= 12.8.6 Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID Collision PoC, Patch Analysis & Rule

CVE-2026-15142 affects the Real Estate Manager Pro plugin (up to v12.8.6) with a CVSS score of 7.5. Authenticated users can escalate privileges to Administrator. Update to the patched version to mitigate this risk.
August 14, 2026

CVE-2026-14279: Wholesale Market <= 2.2.2 Authenticated (Subscriber+) Privilege Escalation via 'role_required' Parameter PoC, Patch Analysis & Rule

CVE-2026-14279 affects the Wholesale Market plugin for WordPress (up to 2.2.2) with a high severity CVSS score of 8.8. Authenticated users can escalate privileges to Administrator; patching is essential for security.
August 14, 2026

CVE-2026-16142: TrueBooker <= 1.2.6 Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter PoC, Patch Analysis & Rule

CVE-2026-16142 affects Truebooker Appointment Booking plugin versions up to 1.2.6, allowing unauthenticated account takeover with a CVSS score of 9.8. Upgrade to 1.2.7 to mitigate this critical vulnerability.
August 14, 2026

CVE-2026-15826: User Profile Builder <= 3.16.4 Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter PoC, Patch Analysis & Rule

CVE-2026-15826 exposes the Profile Builder plugin (up to v3.16.4) to critical authentication bypass, allowing unauthenticated access as the Administrator. Upgrade to v3.16.5 to mitigate this severe risk.
August 14, 2026

CVE-2026-16146: Invisible Anti-Spam & CAPTCHA <= 5.1 Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values PoC, Patch Analysis & Rule

CVE-2026-16146 affects the Gdpr Compliant Recaptcha For All Forms plugin (up to version 5.1) with a medium severity SQL injection risk (CVSS 4.9). Users should upgrade to version 5.1.1 to mitigate potential data exposure.
August 14, 2026

CVE-2026-18387: Groundhogg <= 4.5.14 Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter PoC, Patch Analysis & Rule

CVE-2026-18387 affects the Groundhogg plugin for WordPress (up to 4.5.14) with a medium severity (CVSS 6.5) SQL injection vulnerability. Update to 4.5.15 to mitigate risks of sensitive data exposure.
August 14, 2026

CVE-2026-16586: Contest Gallery ‘cgRealId’ PoC, Patch Analysis & Rule

CVE-2026-16586 affects the Contest Gallery plugin (up to version 30.0.7) with a medium severity rating of 6.5. Authenticated attackers can exploit a SQL injection vulnerability, so upgrade to version 31.0.0 to mitigate risks.
August 14, 2026

CVE-2026-16145: Invisible Anti-Spam & CAPTCHA <= 5.1 Unauthenticated Stored Cross-Site Scripting via 'action' Parameter PoC, Patch Analysis & Rule

CVE-2026-16145 affects the Gdpr Compliant Recaptcha For All Forms plugin (up to 5.1) with a high severity CVSS score of 7.2. Users should update to version 5.1.1 to mitigate the stored XSS vulnerability.
August 14, 2026

CVE-2026-15453: KiviCare <= 4.5.1 Authenticated (Doctor+) SQL Injection via 'searchTerm' Parameter PoC, Patch Analysis & Rule

CVE-2026-15453 affects the Kivicare Clinic Management System (up to version 4.5.1) with a medium severity SQL injection vulnerability. Users should upgrade to version 4.5.2 to mitigate risks of sensitive data exposure.
August 14, 2026

CVE-2026-17090: Beaver Builder Page Builder <= 2.10.2.2 Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter PoC, Patch Analysis & Rule

CVE-2026-17090 affects Beaver Builder Lite up to version 2.10.2.2, allowing authenticated users to exploit stored XSS vulnerabilities. Upgrade to 2.10.3.2 to mitigate risks from this medium severity issue.
August 14, 2026

CVE-2026-15948: Hydra Booking <= 1.2.2 Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter PoC, Patch Analysis & Rule

CVE-2026-15948 affects the Hydra Booking plugin for WordPress (up to v1.2.2) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should update to v1.2.3 to mitigate risks associated with this flaw.
August 14, 2026

CVE-2026-16080: Image Uploader for Welcart <= 1.4.6 Authenticated (Author+) SQL Injection via Attachment 'post_title' Parameter PoC, Patch Analysis & Rule

CVE-2026-16080 affects the Image Uploader for Welcart plugin (up to version 1.4.6) with a medium severity CVSS score of 6.5. Authenticated attackers can exploit SQL injection vulnerabilities, so patching is essential.
August 14, 2026

CVE-2026-8840: Booking calendar, Appointment Booking System <= 3.2.36 Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action PoC, Patch Analysis & Rule

CVE-2026-8840 affects the Booking Calendar plugin for WordPress (up to v3.2.36) with a medium severity (CVSS 5.3) authentication bypass. Unauthenticated attackers can manipulate payment records and reservation statuses. Update to the...
August 14, 2026

CVE-2026-12128: Pinpoint Booking System <= 2.9.9.6.8 Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter PoC, Patch Analysis & Rule

CVE-2026-12128 affects the Pinpoint Booking System plugin for WordPress (up to version 2.9.9.6.8) allowing unauthenticated price manipulation. Users should patch to mitigate this medium severity risk.
August 14, 2026

CVE-2026-15312: Propovoice: All-in-One Client Management System <= 1.7.8 Authenticated (ndpv_manager+) Privilege Escalation via 'role' Parameter PoC, Patch Analysis & Rule

CVE-2026-15312 affects the Propovoice plugin (up to version 1.7.8) with a CVSS score of 8.8. Authenticated users can escalate privileges to administrator. Update to the patched version to mitigate this risk.
August 14, 2026

CVE-2026-14433: Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter PoC, Patch Analysis & Rule

CVE-2026-14433 affects Meeting Scheduler By Vcita plugin versions up to 4.6.0, with a CVSS score of 7.2. Unauthenticated attackers can exploit stored XSS vulnerabilities, making patching essential for security.
August 14, 2026

CVE-2026-15162: Object Sync for Salesforce <= 2.2.13 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

CVE-2026-15162 affects the Object Sync For Salesforce plugin (v2.2.13) with a CVSS score of 7.5. This high-severity SQL injection allows unauthenticated users to extract sensitive data. Update to the patched version to mitigate risks.
August 14, 2026

CVE-2026-15965: MaxUpload <= 1.4.0 Unauthenticated Arbitrary File Upload via 'resumableFilename' Parameter PoC, Patch Analysis & Rule

CVE-2026-15965 affects the Maxupload Upload Larger Files Easily plugin (v1.4.0 and earlier) with a high severity CVSS score of 8.8. Unauthenticated attackers can exploit this file upload vulnerability, potentially leading to remote code...
August 13, 2026

CVE-2026-73403: User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.6 Missing Authorization PoC, Patch Analysis & Rule

CVE-2026-73403 affects the User Registration plugin for WordPress, versions up to 5.2.6, with a medium severity CVSS score of 5.3. Users should upgrade to version 5.2.7 to mitigate unauthorized access risks.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works