Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

August 15, 2026

CVE-2026-15604: Toocheke Companion <= 2.10 Authenticated (Contributor+) Stored Cross-Site Scripting via 'series_bg_color' Post Meta PoC, Patch Analysis & Rule

CVE-2026-15604 affects the Toocheke Companion plugin (up to v2.10) with a medium severity CVSS score of 6.4. Update to v2.11 to mitigate Stored XSS risks that allow authenticated users to inject scripts in the admin dashboard.
August 15, 2026

CVE-2026-16775: Smash Balloon Social Post Feed <= 4.9.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute PoC, Patch Analysis & Rule

CVE-2026-16775 affects the Custom Facebook Feed plugin (up to v4.9.0) with a medium severity (CVSS 6.4) Stored XSS vulnerability. Users should upgrade to v4.10.0 to mitigate risks from authenticated attackers.
August 15, 2026

CVE-2026-16758: Snippet Shortcodes <= 5.2.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

CVE-2026-16758 affects the Shortcode Variables plugin for WordPress (up to version 5.2.0) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability, highlighting the need for immediate patching.
August 15, 2026

CVE-2026-17582: Slider Hero with Video Background, Animation <= 9.1.7 Authenticated (Administrator+) SQL Injection via 'description' Slide Field (Second-Order via Duplicate) PoC, Patch Analysis & Rule

CVE-2026-17582 affects the Slider Hero plugin for WordPress (up to v9.1.7) with a medium severity score of 4.9. Authenticated admins can exploit a SQL injection vulnerability. Upgrade to v9.1.8 to mitigate risks.
August 14, 2026

CVE-2026-18855: Link Library <= 7.9.4 Unauthenticated Arbitrary File Deletion via link_url Parameter PoC, Patch Analysis & Rule

CVE-2026-18855 affects the Link Library plugin for WordPress (up to 7.9.4) with a critical CVSS score of 9.1. It allows unauthenticated file deletion, risking remote code execution. Update to version 7.9.5 to mitigate this issue.
August 14, 2026

CVE-2026-15142: Real Estate Manager Pro <= 12.8.6 Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID Collision PoC, Patch Analysis & Rule

CVE-2026-15142 affects the Real Estate Manager Pro plugin (up to v12.8.6) with a CVSS score of 7.5. Authenticated users can escalate privileges to Administrator. Update to the patched version to mitigate this risk.
August 14, 2026

CVE-2026-14279: Wholesale Market <= 2.2.2 Authenticated (Subscriber+) Privilege Escalation via 'role_required' Parameter PoC, Patch Analysis & Rule

CVE-2026-14279 affects the Wholesale Market plugin for WordPress (up to 2.2.2) with a high severity CVSS score of 8.8. Authenticated users can escalate privileges to Administrator; patching is essential for security.
August 14, 2026

CVE-2026-16142: TrueBooker <= 1.2.6 Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter PoC, Patch Analysis & Rule

CVE-2026-16142 affects Truebooker Appointment Booking plugin versions up to 1.2.6, allowing unauthenticated account takeover with a CVSS score of 9.8. Upgrade to 1.2.7 to mitigate this critical vulnerability.
August 14, 2026

CVE-2026-15826: User Profile Builder <= 3.16.4 Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter PoC, Patch Analysis & Rule

CVE-2026-15826 exposes the Profile Builder plugin (up to v3.16.4) to critical authentication bypass, allowing unauthenticated access as the Administrator. Upgrade to v3.16.5 to mitigate this severe risk.
August 14, 2026

CVE-2026-16146: Invisible Anti-Spam & CAPTCHA <= 5.1 Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values PoC, Patch Analysis & Rule

CVE-2026-16146 affects the Gdpr Compliant Recaptcha For All Forms plugin (up to version 5.1) with a medium severity SQL injection risk (CVSS 4.9). Users should upgrade to version 5.1.1 to mitigate potential data exposure.
August 14, 2026

CVE-2026-18387: Groundhogg <= 4.5.14 Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter PoC, Patch Analysis & Rule

CVE-2026-18387 affects the Groundhogg plugin for WordPress (up to 4.5.14) with a medium severity (CVSS 6.5) SQL injection vulnerability. Update to 4.5.15 to mitigate risks of sensitive data exposure.
August 14, 2026

CVE-2026-16586: Contest Gallery ‘cgRealId’ PoC, Patch Analysis & Rule

CVE-2026-16586 affects the Contest Gallery plugin (up to version 30.0.7) with a medium severity rating of 6.5. Authenticated attackers can exploit a SQL injection vulnerability, so upgrade to version 31.0.0 to mitigate risks.
August 14, 2026

CVE-2026-16145: Invisible Anti-Spam & CAPTCHA <= 5.1 Unauthenticated Stored Cross-Site Scripting via 'action' Parameter PoC, Patch Analysis & Rule

CVE-2026-16145 affects the Gdpr Compliant Recaptcha For All Forms plugin (up to 5.1) with a high severity CVSS score of 7.2. Users should update to version 5.1.1 to mitigate the stored XSS vulnerability.
August 14, 2026

CVE-2026-15453: KiviCare <= 4.5.1 Authenticated (Doctor+) SQL Injection via 'searchTerm' Parameter PoC, Patch Analysis & Rule

CVE-2026-15453 affects the Kivicare Clinic Management System (up to version 4.5.1) with a medium severity SQL injection vulnerability. Users should upgrade to version 4.5.2 to mitigate risks of sensitive data exposure.
August 14, 2026

CVE-2026-17090: Beaver Builder Page Builder <= 2.10.2.2 Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter PoC, Patch Analysis & Rule

CVE-2026-17090 affects Beaver Builder Lite up to version 2.10.2.2, allowing authenticated users to exploit stored XSS vulnerabilities. Upgrade to 2.10.3.2 to mitigate risks from this medium severity issue.
August 14, 2026

CVE-2026-15948: Hydra Booking <= 1.2.2 Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter PoC, Patch Analysis & Rule

CVE-2026-15948 affects the Hydra Booking plugin for WordPress (up to v1.2.2) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should update to v1.2.3 to mitigate risks associated with this flaw.
August 14, 2026

CVE-2026-16080: Image Uploader for Welcart <= 1.4.6 Authenticated (Author+) SQL Injection via Attachment 'post_title' Parameter PoC, Patch Analysis & Rule

CVE-2026-16080 affects the Image Uploader for Welcart plugin (up to version 1.4.6) with a medium severity CVSS score of 6.5. Authenticated attackers can exploit SQL injection vulnerabilities, so patching is essential.
August 14, 2026

CVE-2026-8840: Booking calendar, Appointment Booking System <= 3.2.36 Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action PoC, Patch Analysis & Rule

CVE-2026-8840 affects the Booking Calendar plugin for WordPress (up to v3.2.36) with a medium severity (CVSS 5.3) authentication bypass. Unauthenticated attackers can manipulate payment records and reservation statuses. Update to the...
August 14, 2026

CVE-2026-12128: Pinpoint Booking System <= 2.9.9.6.8 Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter PoC, Patch Analysis & Rule

CVE-2026-12128 affects the Pinpoint Booking System plugin for WordPress (up to version 2.9.9.6.8) allowing unauthenticated price manipulation. Users should patch to mitigate this medium severity risk.
August 14, 2026

CVE-2026-15312: Propovoice: All-in-One Client Management System <= 1.7.8 Authenticated (ndpv_manager+) Privilege Escalation via 'role' Parameter PoC, Patch Analysis & Rule

CVE-2026-15312 affects the Propovoice plugin (up to version 1.7.8) with a CVSS score of 8.8. Authenticated users can escalate privileges to administrator. Update to the patched version to mitigate this risk.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works