Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

May 19, 2026

CVE-2026-8624: LJ comments import: reloaded <= 0.97.1 Reflected Cross-Site Scripting via PHP_SELF Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-8624 in Lj Comments Import Reloaded (CVSS 6.1): LJ comments import: reloaded. Atomic Edge summarizes impact, exploitability, and patch details.
May 19, 2026

CVE-2026-6549: Logo Manager For Enamad <= 0.7.4 Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute PoC, Patch Analysis & Rule

Medium CVE-2026-6549 in Logo Manager For Enamad (CVSS 6.4): Logo Manager For Enamad. Atomic Edge summarizes impact, exploitability, and patch details.
May 18, 2026

CVE-2026-4883: Piotnet Forms <= 2.1.40 Unauthenticated Arbitrary File Upload via Form File Upload PoC, Patch Analysis & Rule

Critical CVE-2026-4883 in Piotnetforms Pro (CVSS 9.8): Piotnet Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 18, 2026

CVE-2026-4885: Piotnet Addons for Elementor Pro <= 7.1.70 Unauthenticated Arbitrary File Upload via Form File Upload PoC, Patch Analysis & Rule

Critical CVE-2026-4885 in Piotnet Addons For Elementor Pro (CVSS 9.8): Piotnet Addons for Elementor Pro. Atomic Edge summarizes impact, exploitability, and patch details.
May 18, 2026

CVE-2026-42639: GD Rating System <= 3.6.2 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-42639 in Gd Rating System (CVSS 7.5): GD Rating System. Atomic Edge summarizes impact, exploitability, and patch details. Update to 3.7.
May 18, 2026

CVE-2026-40776: Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.8 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-40776 in Wp Event Solution (CVSS 5.3): Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered). Atomic Edge summarizes impact, exploitability, and patch details. Update to 4.1.9.
May 18, 2026

CVE-2026-8912: Contest Gallery <= 28.1.6 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-8912 in Contest Gallery (CVSS 7.5): Contest Gallery. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 28.1.7.
May 18, 2026

CVE-2026-42660: Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 Authenticated (Subscriber+) Sensitive Information Exposure PoC, Patch Analysis & Rule

Medium CVE-2026-42660 in Contest Gallery (CVSS 4.3): Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 29.0.0.
May 18, 2026

CVE-2026-42654: Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments <= 2.7.5 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-42654 in Wallet System For Woocommerce (CVSS 4.3): Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback.... Atomic Edge summarizes impact, exploitability, and patch details, with...
May 18, 2026

CVE-2026-42629: PowerPack Pro for Elementor < v2.13.0 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-42629 in Powerpack Elements (CVSS 5.3): PowerPack Pro for Elementor < v2.13.0 - Missing Authorization. Atomic Edge summarizes impact, exploitability, and patch details.
May 18, 2026

CVE-2026-40795: Booking for Appointments and Events Calendar – Amelia <= 2.2 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-40795 in Ameliabooking (CVSS 4.3): Booking for Appointments and Events Calendar – Amelia. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.2.1.
May 18, 2026

CVE-2026-42655: Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management <= 4.6.19 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-42655 in Wp Payment Form (CVSS 5.3): Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations.... Atomic Edge summarizes impact, exploitability, and patch details. Update to 4.6.20.
May 18, 2026

CVE-2026-5306: Check & Log Email – Easy Email Testing & Mail logging < 2.0.13 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

High CVE-2026-5306 in Check Email (CVSS 7.2): Check & Log Email – Easy Email Testing & Mail logging < 2.0.13 - Unauthenticated Stored Cross-Site.... Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.0.13.
May 18, 2026

CVE-2026-42647: JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.7.7 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-42647 in Joomsport Sports League Results Management (CVSS 7.5): JoomSport – for Sports: Team & League, Football, Hockey & more. Atomic Edge summarizes impact, exploitability, and patch details.
May 18, 2026

CVE-2026-42384: Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin < 1.6.11.2 Unauthenticated Sensitive Information Exposure PoC, Patch Analysis & Rule

Medium CVE-2026-42384 in Simply Schedule Appointments (CVSS 5.3): Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin < 1.6.11.2 -.... Atomic Edge summarizes impact, exploitability, and patch details. Update to...
May 18, 2026

CVE-2026-42412: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-42412 in Wp User Frontend (CVSS 5.3): User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
May 18, 2026

CVE-2026-42410: TheGem Theme Elements < 5.12.1.1 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2026-42410 in Thegem Elements Elementor (CVSS 6.4): TheGem Theme Elements < 5.12.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting. Atomic Edge summarizes impact, exploitability, and patch details.
May 18, 2026

CVE-2026-42649: Favicon Rotator <= 1.2.11 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

High CVE-2026-42649 in Favicon Rotator (CVSS 7.2): Favicon Rotator. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.2.12.
May 18, 2026

CVE-2026-42379: Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! <= 3.6.1 Authenticated (Contributor+) Information Exposure PoC, Patch Analysis & Rule

Medium CVE-2026-42379 in Templately (CVSS 4.3): Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud!. Atomic Edge summarizes impact, exploitability, and patch details. Update to 3.6.2.
May 18, 2026

CVE-2026-42386: Order Delivery Date for WooCommerce <= 4.5.1 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-42386 in Order Delivery Date For Woocommerce (CVSS 7.5): Order Delivery Date for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.5.2.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works