Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

May 16, 2026

CVE-2025-68049: bunny.net – WordPress CDN Plugin <= 2.3.6 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2025-68049 in Bunnycdn (CVSS 4.3): bunny.net – WordPress CDN Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.3.7.
May 16, 2026

CVE-2025-66105: Bus Ticket Booking with Seat Reservation < 5.6.8 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2025-66105 in Bus Ticket Booking With Seat Reservation (CVSS 5.3): Bus Ticket Booking with Seat Reservation < 5.6.8 - Missing Authorization. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
May 16, 2026

CVE-2025-62127: WEN Logo Slider <= 3.4.0 Authenticated (Author+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule

Medium CVE-2025-62127 in Wen Logo Slider (CVSS 6.4): WEN Logo Slider. Atomic Edge summarizes impact, exploitability, and patch details. Update to 3.5.
May 15, 2026

CVE-2026-4029: Database Backup for WordPress <= 2.5.2 Missing Authorization to Unauthenticated Database Export PoC, Patch Analysis & Rule

High CVE-2026-4029 in Wp Db Backup (CVSS 7.5): Database Backup for WordPress. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.5.3.
May 15, 2026

CVE-2025-4202: Multicollab: Content Team Collaboration and Editorial Workflow <= 5.2 Missing Authorization to Authenticated (Subscriber+) Collaboration Comment PoC, Patch Analysis & Rule

Medium CVE-2025-4202 in Commenting Feature (CVSS 4.3): Multicollab: Content Team Collaboration and Editorial Workflow. Atomic Edge summarizes impact, exploitability, and patch details. Update to 5.3.
May 15, 2026

CVE-2026-8681: Essential Chat Support <= 1.0.1 Missing Authorization to Unauthenticated Settings Reset via 'ecs_reset_settings' Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-8681 in Essential Chat Support (CVSS 5.3): Essential Chat Support. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 15, 2026

CVE-2026-6913: Shortcodely <= 1.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_area' Shortcode Attribute PoC, Patch Analysis & Rule

Medium CVE-2026-6913 in Shortcodely (CVSS 6.4): Shortcodely. Atomic Edge summarizes impact, exploitability, and patch details.
May 15, 2026

CVE-2026-4609: ProfileGrid <= 5.9.8.4 Missing Authorization to Authenticated (Subscriber+) Arbitrary Group Joining PoC, Patch Analysis & Rule

High CVE-2026-4609 in Profilegrid User Profiles Groups And Communities (CVSS 7.1): ProfileGrid. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.9.8.5.
May 15, 2026

CVE-2026-6177: Custom Twitter Feeds <= 2.5.4 Unauthenticated Stored Cross-Site Scripting via Cached Tweet Text PoC, Patch Analysis & Rule

High CVE-2026-6177 in Custom Twitter Feeds (CVSS 7.2): Custom Twitter Feeds. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.5.5.
May 15, 2026

CVE-2025-14767: WPC Badge Management for WooCommerce <= 3.1.6 Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'text' Attribute PoC, Patch Analysis & Rule

Medium CVE-2025-14767 in Wpc Badge Management (CVSS 5.5): WPC Badge Management for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details. Update to 3.1.7.
May 15, 2026

CVE-2026-6708: HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 Missing Authorization to Unauthenticated Arbitrary Classroom Deletion via 'id' Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-6708 in Hel Online Classroom (CVSS 5.3): HEL Online Classroom: AI-powered Online Classrooms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 15, 2026

CVE-2026-6710: Skysa Text Ticker App <= 1.4 Cross-Site Request Forgery to Settings Modification via 'Save Settings' Form PoC, Patch Analysis & Rule

Medium CVE-2026-6710 in Skysa Text Ticker App (CVSS 4.3): Skysa Text Ticker App. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 15, 2026

CVE-2026-6709: Coinbase Commerce for Contact Form 7 <= 1.1.2 Missing Authorization to Authenticated (Subscriber+) API Key Modification via 'cccf7_api_key' Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-6709 in Coinbase Commerce For Contact Form 7 (CVSS 4.3): Coinbase Commerce for Contact Form 7. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 15, 2026

CVE-2026-7635: coreActivity: Activity Logging for WordPress <= 3.0 Unauthenticated PHP Object Injection via 'user_agent' Log Meta Field PoC, Patch Analysis & Rule

High CVE-2026-7635 in Coreactivity (CVSS 8.1): coreActivity: Activity Logging for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.1.
May 15, 2026

CVE-2026-5715: Voyage Plus <= 1.0.6 Authenticated (Contributor+) Stored Cross-Site Scripting via 'post-content' Shortcode PoC, Patch Analysis & Rule

Medium CVE-2026-5715 in Voyage Plus (CVSS 6.4): Voyage Plus. Atomic Edge summarizes impact, exploitability, and patch details.
May 15, 2026

CVE-2026-5340: Fancy Image Show <= 9.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule

Medium CVE-2026-5340 in Fancy Image Show (CVSS 6.4): Fancy Image Show. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 15, 2026

CVE-2026-5693: Smart Appointment & Booking <= 1.0.8 Missing Authorization to Unauthenticated Arbitrary Booking Cancellation PoC, Patch Analysis & Rule

Medium CVE-2026-5693 in Smart Appointment Booking (CVSS 5.3): Smart Appointment & Booking. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 15, 2026

CVE-2026-7661: Bootstrap Shortcode <= 1.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'box' Shortcode PoC, Patch Analysis & Rule

Medium CVE-2026-7661 in Bootstrap Shortcode (CVSS 6.4): Bootstrap Shortcode. Atomic Edge summarizes impact, exploitability, and patch details.
May 15, 2026

CVE-2026-7659: Advanced Social Media Icons <= 1.2 Authenticated (Contributor+) Stored Cross-Site Scripting via 'social' Shortcode PoC, Patch Analysis & Rule

Medium CVE-2026-7659 in Advanced Social Media Icons (CVSS 6.4): Advanced Social Media Icons. Atomic Edge summarizes impact, exploitability, and patch details.
May 15, 2026

CVE-2026-5028: Eight Day Week Print Workflow <= 1.2.6 Authenticated (Subscriber+) SQL Injection via 'title' Parameter PoC, Patch Analysis & Rule

Medium CVE-2026-5028 in Eight Day Week Print Workflow (CVSS 6.5): Eight Day Week Print Workflow. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.3.0.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works