
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
May 20, 2026
CVE-2026-6395: Word 2 Cash <= 0.9.2 Cross-Site Request Forgeryto Stored Cross-Site Scripting via Settings Page PoC, Patch Analysis & Rule
Medium CVE-2026-6395 in Word 2 Cash (CVSS 6.1): Word 2 Cash. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 20, 2026
CVE-2026-6397: Sticky <= 2.5.6 Authenticated (Contributor+) Stored Cross-Site Scripting via 'readmoretext' Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-6397 in Sticky (CVSS 6.4): Sticky. Atomic Edge summarizes impact, exploitability, and patch details.
May 19, 2026
CVE-2026-7637: Boost <= 2.0.3 Unauthenticated PHP Object Injection via STYXKEY-BOOST_USER_LOCATION Cookie PoC, Patch Analysis & Rule
Critical CVE-2026-7637 in Boost (CVSS 9.8): Boost. Atomic Edge summarizes impact, exploitability, and patch details.
May 19, 2026
CVE-2026-7613: Cost of Goods by PixelYourSite <= 1.2.12 Unauthenticated Stored Cross-Site Scripting via Cost of Goods Import PoC, Patch Analysis & Rule
High CVE-2026-7613 in Pixel Cost Of Goods (CVSS 7.2): Cost of Goods by PixelYourSite. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 19, 2026
CVE-2026-7522: Advanced Database Cleaner – Premium <= 4.1.0 Authenticated (Subscriber+) Local File Inclusion via 'template' PoC, Patch Analysis & Rule
High CVE-2026-7522 in Advanced Database Cleaner Premium (CVSS 8.8): Advanced Database Cleaner – Premium. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 19, 2026
CVE-2026-6566: Photo Gallery, Sliders, Proofing and Themes <= 4.2.0 Insecure Direct Object Reference to Authenticated (Subscriber+) Image Deletion via REST API PoC, Patch Analysis & Rule
Medium CVE-2026-6566 in Nextgen Gallery (CVSS 4.3): Photo Gallery, Sliders, Proofing and Themes. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.2.1.
May 19, 2026
CVE-2026-5075: All in One SEO <= 4.9.7 Authenticated (Contributor+) Sensitive Information Exposure via 'internalOptions' Localized Script Data PoC, Patch Analysis & Rule
Medium CVE-2026-5075 in All In One Seo Pack (CVSS 4.3): All in One SEO. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 19, 2026
CVE-2026-5200: AcyMailing <= 10.8.2 Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via 'acymailing_router' PoC, Patch Analysis & Rule
High CVE-2026-5200 in Acymailing (CVSS 8.8): AcyMailing. Atomic Edge summarizes impact, exploitability, and patch details. Update to 10.9.0.
May 19, 2026
CVE-2026-2955: AI Chatbot & Workflow Automation by AIWU <= 1.4.14 Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' Header PoC, Patch Analysis & Rule
Medium CVE-2026-2955 in Ai Copilot Content Generator (CVSS 6.4): AI Chatbot & Workflow Automation by AIWU. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.4.15.
May 19, 2026
CVE-2025-15369: Xpro Addons — 140+ Widgets for Elementor <= 1.5.0 Missing Authorization to Unauthenticated Xpro Template Creation PoC, Patch Analysis & Rule
Medium CVE-2025-15369 in Xpro Elementor Addons (CVSS 5.3): Xpro Addons — 140+ Widgets for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 19, 2026
CVE-2026-9010: Boost <= 2.0.3 Unauthenticated Blind SQL Injection via Multiple Parameters PoC, Patch Analysis & Rule
High CVE-2026-9010 in Boost (CVSS 7.5): Boost. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 19, 2026
CVE-2026-3985: Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 Unauthenticated SQL Injection via 'checkout_uuid' Parameter PoC, Patch Analysis & Rule
High CVE-2026-3985 in Creative Mail By Constant Contact (CVSS 7.5): Creative Mail – Easier WordPress & WooCommerce Email Marketing. Atomic Edge summarizes impact, exploitability, and patch details.
May 19, 2026
CVE-2026-7284: Easy Elements for Elementor <= 1.4.4 Unauthenticated Privilege Escalation via easyel_handle_register PoC, Patch Analysis & Rule
Critical CVE-2026-7284 in Easy Elements (CVSS 9.8): Easy Elements for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 19, 2026
CVE-2026-6405: Anomify AI <= 0.3.6 Cross-Site Request Forgery PoC, Patch Analysis & Rule
Medium CVE-2026-6405 in Anomify (CVSS 4.3): Anomify AI. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 19, 2026
CVE-2026-8610: TypeSquare Webfonts for ConoHa <= 2.0.4 Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification via 'fontThemeUseType' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-8610 in Ts Webfonts For Conoha (CVSS 4.3): TypeSquare Webfonts for ConoHa. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 19, 2026
CVE-2026-7467: Read More & Accordion <= 3.5.7 Privilege Escalation via importData PoC, Patch Analysis & Rule
High CVE-2026-7467 in Expand Maker (CVSS 8.8): Read More & Accordion. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 19, 2026
CVE-2026-8627: Correct Prices <= 1.0 Reflected Cross-Site Scripting via PHP_SELF Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-8627 in Correct Prices (CVSS 6.1): Correct Prices. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 19, 2026
CVE-2026-7472: Read More & Accordion <= 3.5.7 Authenticated (Administrator+) SQL Injection via 'orderby' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-7472 in Expand Maker (CVSS 4.9): Read More & Accordion. Atomic Edge summarizes impact, exploitability, and patch details.
May 19, 2026
CVE-2026-6728: Slider Revolution <= 7.0.9 Unauthenticated Sensitive Information Exposure via 'sliders/stream' PoC, Patch Analysis & Rule
Medium CVE-2026-6728 in Revslider (CVSS 5.3): Slider Revolution. Atomic Edge summarizes impact, exploitability, and patch details.
May 19, 2026
CVE-2026-8626: SponsorMe <= 0.5.2 Reflected Cross-Site Scripting via PHP_SELF Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-8626 in Sponsorme (CVSS 6.1): SponsorMe. Atomic Edge summarizes impact, exploitability, and patch details.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
