
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
May 13, 2026
CVE-2026-6271: Career Section <= 1.7 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule
Critical CVE-2026-6271 in Career Section (CVSS 9.8): Career Section. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.8.
May 13, 2026
CVE-2026-3892: Motors – Car Dealer, Classifieds & Listing <= 1.4.107 Authenticated (Subscriber+) Arbitrary File Deletion via 'stm_dealer_logo_path' Parameter PoC, Patch Analysis & Rule
High CVE-2026-3892 in Motors Car Dealership Classified Listings (CVSS 8.1): Motors – Car Dealer, Classifieds & Listing. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.4.108.
May 12, 2026
CVE-2026-6965: Tutor LMS <= 3.9.9 Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-6965 in Tutor (CVSS 5.3): Tutor LMS. Atomic Edge summarizes impact, exploitability, and patch details. Update to 3.9.10.
May 12, 2026
CVE-2026-4798: Avada Builder <= 3.15.1 Unauthenticated SQL Injection via 'product_order' Parameter PoC, Patch Analysis & Rule
High CVE-2026-4798 in Fusion Builder (CVSS 7.5): Avada Builder. Atomic Edge summarizes impact, exploitability, and patch details.
May 12, 2026
CVE-2026-6929: JoomSport <= 5.7.7 Unauthenticated SQL Injection via 'sortf' Parameter PoC, Patch Analysis & Rule
High CVE-2026-6929 in Joomsport Sports League Results Management (CVSS 7.5): JoomSport. Atomic Edge summarizes impact, exploitability, and patch details.
May 12, 2026
CVE-2025-14033: ilGhera Support System for WooCommerce <= 1.3.0 Missing Authorization to Unauthenticated Sensitive Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2025-14033 in Wc Support System (CVSS 5.3): ilGhera Support System for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.3.1.
May 12, 2026
CVE-2026-4782: Avada Builder <= 3.15.2 Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-4782 in Fusion Builder (CVSS 6.5): Avada Builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 12, 2026
CVE-2025-14755: Cost Calculator Builder <= 4.0.1 Unauthenticated Price Manipulation and Insecure Direct Object Reference PoC, Patch Analysis & Rule
Medium CVE-2025-14755 in Cost Calculator Builder (CVSS 5.3): Cost Calculator Builder. Atomic Edge summarizes impact, exploitability, and patch details. Update to 4.0.2.
May 12, 2026
CVE-2026-6962: Cost of Goods: Product Cost & Profit Calculator for WooCommerce <= 4.1.0 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-6962 in Cost Of Goods For Woocommerce (CVSS 6.4): Cost of Goods: Product Cost & Profit Calculator for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
May 12, 2026
CVE-2026-7051: Blog2Social: Social Media Auto Post & Scheduler <= 8.9.0 Missing Authorization to Authenticated (Subscriber+) Delete Arbitrary B2S Post Records via 'postId' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-7051 in Blog2social (CVSS 5.4): Blog2Social: Social Media Auto Post & Scheduler. Atomic Edge summarizes impact, exploitability, and patch details. Update to 8.9.1.
May 12, 2026
CVE-2025-9988: Broadstreet <= 1.53.1 Missing Authorization to Authenticated (Subscriber+) Advertiser Creation PoC, Patch Analysis & Rule
Medium CVE-2025-9988 in Broadstreet (CVSS 4.3): Broadstreet. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.53.2.
May 12, 2026
CVE-2026-1250: Court Reservation – Manage Your Court Bookings Online <= 1.10.11 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
High CVE-2026-1250 in Court Reservation (CVSS 7.5): Court Reservation – Manage Your Court Bookings Online. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.10.12.
May 12, 2026
CVE-2025-9989: Broadstreet <= 1.53.1 Authenticated (Admin+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-9989 in Broadstreet (CVSS 4.4): Broadstreet. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.53.2.
May 12, 2026
CVE-2026-5371: MonsterInsights <= 10.1.2 Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure And Plugin Integration Reset PoC, Patch Analysis & Rule
High CVE-2026-5371 in Google Analytics For Wordpress (CVSS 7.1): MonsterInsights. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 10.1.3.
May 12, 2026
CVE-2025-9987: Broadstreet <= 1.53.1 Authenticated (Subscriber+) Information Disclosure PoC, Patch Analysis & Rule
Medium CVE-2025-9987 in Broadstreet (CVSS 5.3): Broadstreet. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.53.2.
May 12, 2026
CVE-2026-7619: Charitable <= 1.8.10.4 Authenticated (Custom+) SQL Injection via 's' Search Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-7619 in Charitable (CVSS 6.5): Charitable. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.8.10.5.
May 12, 2026
CVE-2025-15463: Advanced Custom Fields: Extended <= 0.9.2.3 Unauthenticated Arbitrary Shortcode Execution PoC, Patch Analysis & Rule
Medium CVE-2025-15463 in Acf Extended (CVSS 6.5): Advanced Custom Fields: Extended. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 0.9.2.4.
May 12, 2026
CVE-2026-3425: RTMKit Addons for Elementor <= 2.0.2 Authenticated (Author+) Local File Inclusion via 'path' PoC, Patch Analysis & Rule
High CVE-2026-3425 in Rometheme For Elementor (CVSS 8.8): RTMKit Addons for Elementor. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.0.3.
May 12, 2026
CVE-2026-6828: Fluent Forms <= 6.2.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-6828 in Fluentform (CVSS 6.4): Fluent Forms. Atomic Edge summarizes impact, exploitability, and patch details. Update to 6.2.2.
May 12, 2026
CVE-2026-4608: ProfileGrid <= 5.9.8.4 Authenticated (Subscriber+) SQL Injection via 'rid' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-4608 in Profilegrid User Profiles Groups And Communities (CVSS 6.5): ProfileGrid. Atomic Edge summarizes impact, exploitability, and patch details. Update to 5.9.8.5.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
