
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
July 20, 2026
CVE-2026-57681: GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.161 Authenticated (Subscriber+) Server-Side Request Forgery PoC, Patch Analysis & Rule
CVE-2026-57681 affects the GeoDirectory plugin for WordPress (up to version 2.8.161) with a medium severity CVSS score of 6.4. Authenticated users can exploit this SSRF vulnerability, so update to version 2.8.162 to mitigate risks.
July 20, 2026
CVE-2026-42740: Tainacan <= 1.0.3 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-42740 affects the Tainacan plugin for WordPress (up to 1.0.3) with a high severity SQL injection vulnerability (CVSS 7.5). Update to version 1.1.0 to mitigate potential data exposure.
July 20, 2026
CVE-2026-57722: Enable Media Replace <= 4.2.1 Authenticated (Editor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-57722 affects the Enable Media Replace plugin for WordPress (up to 4.2.1) with a CVSS score of 4.4. Authenticated attackers can exploit a Stored XSS vulnerability, impacting multi-site setups. Update to 4.2.2 to mitigate.
July 20, 2026
CVE-2026-57355: Classified Listing – AI-Powered Classified ads & Business Directory <= 5.4.2 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-57355 affects the Classified Listing plugin (up to version 5.4.2) with a CVSS score of 4.3. Patch to version 5.4.3 to mitigate unauthorized access risks from authenticated users.
July 20, 2026
CVE-2026-57359: ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema <= 2.3.10 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-57359 reveals a high-severity XSS vulnerability in the ReviewX plugin for WordPress, affecting versions up to 2.3.10. Upgrade to 2.3.11 to mitigate the risk of script injection by unauthenticated attackers.
July 20, 2026
CVE-2026-57360: eCommerce Product Catalog Plugin for WordPress <= 3.5.4 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-57360 affects the Ecommerce Product Catalog Plugin for WordPress (up to version 3.5.4) with a CVSS score of 7.2. Patch to version 3.5.5 to mitigate the risk of stored cross-site scripting attacks.
July 20, 2026
CVE-2026-57358: SysBasics Customize My Account for WooCommerce – Live My Account Customizer <= 4.3.9 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-57358 affects the Customize My Account For WooCommerce plugin (v4.3.9 and earlier) with a CVSS score of 6.1. Users should update to the patched version to mitigate the reflected XSS risk.
July 20, 2026
CVE-2026-57737: Shortcodes and extra features for Phlox theme <= 2.17.21 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-57737 affects Auxin Elements plugin versions up to 2.17.21, with a CVSS score of 6.4. This medium severity stored XSS vulnerability allows authenticated users to inject scripts, impacting site security. Patching is essential.
July 20, 2026
CVE-2026-57361: Survey Maker by AYS <= 5.2.2.5 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-57361 affects Survey Maker by AYS versions up to 5.2.2.5, with a CVSS score of 7.2. This high-severity XSS vulnerability allows unauthenticated attackers to inject scripts. Update to version 5.2.2.6 to mitigate risks.
July 20, 2026
CVE-2026-57751: Heateor Social Login WordPress <= 1.1.39 Cross-Site Request Forgery PoC, Patch Analysis & Rule
CVE-2026-57751 affects Heateor Social Login plugin versions up to 1.1.39, with a CVSS score of 4.3. This medium severity CSRF vulnerability allows unauthorized actions if an admin is tricked. Update to the patched version to mitigate.
July 20, 2026
CVE-2026-57348: Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 3.0.4 Unauthenticated Server-Side Request Forgery PoC, Patch Analysis & Rule
CVE-2026-57348 affects the Paid Member Subscriptions plugin (up to v3.0.4) with a medium severity CVSS score of 6.1. Unauthenticated attackers can exploit this SSRF vulnerability, so update to v3.0.5 to mitigate risks.
July 20, 2026
CVE-2026-27409: Advanced Booking & Appointment System – Webba Booking Calendar <= 6.4.13 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-27409 affects Webba Booking Lite versions up to 6.4.13, allowing unauthorized access due to a missing capability check. Upgrade to 6.4.14 to mitigate potential disruptions to calendar integrations.
July 20, 2026
CVE-2026-57366: WPAdverts – Classifieds Plugin <= 2.3.1 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-57366 affects the WPAdverts plugin for WordPress, versions 2.3.1 and earlier, with a CVSS score of 7.2. Users should upgrade to version 2.3.2 to mitigate the high-severity stored XSS vulnerability.
July 20, 2026
CVE-2026-57736: HubSpot All-In-One Marketing – Forms, Popups, Live Chat <= 11.3.56 Authenticated (Contributor+) Information Exposure PoC, Patch Analysis & Rule
CVE-2026-57736 affects the Leadin plugin for WordPress (up to version 11.3.56) with a medium severity CVSS score of 4.3. Authenticated attackers can access sensitive data; update to version 11.3.58 to mitigate this risk.
July 20, 2026
CVE-2026-57354: JetReviews <= 3.0.0.1 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-57354 affects the Jet Reviews plugin for WordPress (up to version 3.0.0.1) with a CVSS score of 6.4. Authenticated attackers can exploit this stored XSS vulnerability, so ensure timely patching to mitigate risks.
July 20, 2026
CVE-2026-57351: HandL UTM Grabber / Tracker <= 2.9.2 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-57351 affects the HandL UTM Grabber plugin (up to v2.9.2) with a CVSS score of 7.2. This high-severity XSS vulnerability allows attackers to inject scripts. Update to v2.9.3 to mitigate risks.
July 20, 2026
CVE-2026-57692: Private Content <= 9.9.2 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule
CVE-2026-57692 reveals a critical privilege escalation vulnerability in the Private Content plugin for WordPress (versions up to 9.9.2). Unauthenticated attackers can gain admin access. Update to the patched version to mitigate risks.
July 20, 2026
CVE-2026-57353: Link Whisper Premium <= 2.9.0 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-57353 affects Link Whisper Premium plugin versions up to 2.9.0, allowing authenticated attackers to perform unauthorized actions. Users should update to the patched version to mitigate this medium severity vulnerability.
July 20, 2026
CVE-2026-57356: MoreConvert Wishlist for WooCommerce <= 1.9.19 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-57356 affects the Smart Wishlist For More Convert plugin (v1.9.19) with a CVSS score of 7.2. Unauthenticated attackers can exploit this high-severity XSS vulnerability. Update to v1.9.20 to mitigate risks.
July 20, 2026
CVE-2026-57347: MotoPress Hotel Booking <= 6.0.3 Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule
CVE-2026-57347 affects the MotoPress Hotel Booking Lite plugin (up to 6.0.3) with a medium severity CVSS of 4.3. Authenticated attackers can expose sensitive data; update to 6.0.4 to mitigate this risk.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
