Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

2026-03-23

CVE-2026-3079: LearnDash LMS <= 5.0.3 – Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter (sfwd-lms)

The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' parameter in the 'learndash_propanel_template' AJAX action in all versions up to, and including, 5.0.3. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
2026-03-23

CVE-2026-4283: WP DSGVO Tools (GDPR) <= 3.1.38 – Missing Authorization to Unauthenticated Account Destruction of Non-Admin Users (shapepress-dsgvo)

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the intended email-confirmation flow and immediately triggers irreversible account anonymization. This makes it possible for unauthenticated…
2026-03-23

CVE-2026-32533: LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 – Authenticated (Subscriber+) Insecure Direct Object Reference (latepoint)

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.2.6 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform unauthorized actions.
2026-03-23

CVE-2026-25334: Salon Booking System Pro < 10.30.12 – Missing Authorization (salon-booking-plugin-pro)

The Salon Booking System Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 10.30.12 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-23

CVE-2026-32485: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 – Missing Authorization (wp-user-frontend)

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-23

CVE-2026-25327: Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.9 – Missing Authorization (restaurant-reservations)

The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.7.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-23

CVE-2026-25026: Team – Team Members Showcase Plugin <= 5.0.11 – Missing Authorization (tlp-team)

The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.11. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-23

CVE-2026-32484: weForms – Easy Drag & Drop Contact Form Builder For WordPress <= 1.6.26 – Unauthenticated PHP Object Injection (weforms)

The weForms – Easy Drag & Drop Contact Form Builder For WordPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.26 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software.…
2026-03-23

CVE-2026-32535: JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.3 – Authenticated (Subscriber+) Insecure Direct Object Reference (js-support-ticket)

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.3 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform unauthorized actions.
2026-03-23

CVE-2026-25376: Addon Jobsearch Chat <= 3.0 – Reflected Cross-Site Scripting (addon-jobsearch-chat)

The Addon Jobsearch Chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action…

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works