Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

April 26, 2026

CVE-2025-63029: WCFM Marketplace – Multivendor Marketplace for WooCommerce <= 3.7.1 – Authenticated (Store vendor+) SQL Injection (wc-multivendor-marketplace)

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with store vendor-level access and above,…
April 26, 2026

CVE-2026-40784: FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration <= 1.91.2 – Authenticated (Board Member+) Insecure Direct Object Reference (fluent-boards)

The FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.91.2 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Custom-level access and above, to perform…
April 26, 2026

CVE-2026-3830: Product Filter for WooCommerce by WBW < 3.1.3 – Unauthenticated SQL Injection (woo-product-filter)

The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to SQL Injection in versions up to 3.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries…
April 26, 2026

CVE-2026-39531: WP Directory Kit <= 1.5.0 – Unauthenticated SQL Injection (wpdirectorykit)

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that…
April 26, 2026

CVE-2026-6370: Mini Ajax Cart for WooCommerce <= 1.3.4 – Authenticated (Author+) Stored Cross-Site Scripting (mini-ajax-woo-cart)

The Mini Ajax Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user…
April 26, 2026

CVE-2025-15441: Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder < 1.15.38 – Unauthenticated SQL Injection (form-maker)

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to 1.15.38 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional…
April 26, 2026

CVE-2026-39511: WP Photo Album Plus <= 9.1.08.001 – Unauthenticated SQL Injection (wp-photo-album-plus)

The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.1.08.001 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries…
April 26, 2026

CVE-2026-39468: Meta Box <= 5.11.1 – Authenticated (Contributor+) Arbitrary File Deletion (meta-box)

The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 5.11.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the…
April 26, 2026

CVE-2026-39525: Booking Activities <= 1.16.48.1 – Missing Authorization (booking-activities)

The Booking Activities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.16.48.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
April 26, 2026

CVE-2026-39494: Product Filter for WooCommerce by WBW <= 3.1.2 – Unauthenticated SQL Injection (woo-product-filter)

The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already…
April 26, 2026

CVE-2026-39491: Jupiter X Core <= 4.14.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting (jupiterx-core)

The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an…
April 26, 2026

CVE-2026-39474: Post Duplicator <= 3.0.10 – Authenticated (Contributor+) PHP Object Injection (post-duplicator)

The Post Duplicator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.10 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain…
April 26, 2026

CVE-2024-49242: Digital Lottery <= 3.0.5 – Unauthenticated Arbitrary File Upload (digital-lottery)

The Digital Lottery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.0.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
April 25, 2026

CVE-2026-5721: wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 6.5.0.4 – Unauthenticated Stored Cross-Site Scripting via CSV/Excel Data Import (wpdatatables)

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.5.0.4. This is due to insufficient input sanitization and output escaping in the prepareCellOutput() method of the LinkWDTColumn, ImageWDTColumn, and EmailWDTColumn classes. This makes it possible for…
April 25, 2026

CVE-2024-31115: Chauffeur Taxi Booking System for WordPress <= 7.2 – Unauthenticated Arbitrary File Upload (chauffeur-booking-system)

The Chauffeur Taxi Booking System for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 7.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
April 25, 2026

CVE-2024-32692: Chauffeur Taxi Booking System for WordPress <= 6.9 – Authentication Bypass (chauffeur-booking-system)

The Chauffeur Taxi Booking System for WordPress plugin for WordPress is vulnerable to authenticated bypass in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's identity. This makes it possible for unauthenticated attackers to perform unauthorized actions.
April 25, 2026

CVE-2025-1564: SetSail Membership <= 1.0.3 – Authentication Bypass via Account Takeover (setsail-membership)

The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a users identity through the social login. This makes it possible for unauthenticated attackers to log in as any user, including administrators and take over access to their account.
April 25, 2026

CVE-2025-5955: Service Finder SMS System <= 2.0.0 – Authentication Bypass (aone-sms)

The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to the plugin not verifying a user's phone number before logging them in. This makes it possible for unauthenticated attackers to login as arbitrary users.
April 24, 2026

CVE-2026-4139: mCatFilter <= 0.5.2 – Cross-Site Request Forgery via compute_post() Function (mcatfilter)

The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability checks in the compute_post() function, which processes settings updates. The compute_post() function is called in the plugin constructor on every page load via the…
April 24, 2026

CVE-2026-4082: ER Swiffy Insert <= 1.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes (er-swiffy-insert)

The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swiffy] shortcode in all versions up to and including 1.0.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes ('n', 'w', 'h'). These attributes are extracted using extract() and directly interpolated into the HTML output…

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works