
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
August 14, 2026
CVE-2026-14433: Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter PoC, Patch Analysis & Rule
CVE-2026-14433 affects Meeting Scheduler By Vcita plugin versions up to 4.6.0, with a CVSS score of 7.2. Unauthenticated attackers can exploit stored XSS vulnerabilities, making patching essential for security.
August 14, 2026
CVE-2026-15162: Object Sync for Salesforce <= 2.2.13 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
CVE-2026-15162 affects the Object Sync For Salesforce plugin (v2.2.13) with a CVSS score of 7.5. This high-severity SQL injection allows unauthenticated users to extract sensitive data. Update to the patched version to mitigate risks.
August 14, 2026
CVE-2026-15965: MaxUpload <= 1.4.0 Unauthenticated Arbitrary File Upload via 'resumableFilename' Parameter PoC, Patch Analysis & Rule
CVE-2026-15965 affects the Maxupload Upload Larger Files Easily plugin (v1.4.0 and earlier) with a high severity CVSS score of 8.8. Unauthenticated attackers can exploit this file upload vulnerability, potentially leading to remote code...
August 13, 2026
CVE-2026-73403: User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.6 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-73403 affects the User Registration plugin for WordPress, versions up to 5.2.6, with a medium severity CVSS score of 5.3. Users should upgrade to version 5.2.7 to mitigate unauthorized access risks.
August 13, 2026
CVE-2026-12743: affiliate-toolkit <= 3.8.8 Authenticated (Administrator+) SQL Injection via 'orderby' Parameter PoC, Patch Analysis & Rule
CVE-2026-12743 affects the Affiliate Toolkit Starter plugin (up to v3.8.8) with a medium severity SQL injection vulnerability. Update to v3.8.9 to mitigate risks of unauthorized data access.
August 13, 2026
CVE-2026-12949: Wishlist Member X <= 3.34.1 Unauthenticated Account Takeover via 'mergewith' Parameter PoC, Patch Analysis & Rule
CVE-2026-12949 affects Wishlist Member X plugin versions up to 3.34.1, with a critical CVSS score of 9.8. Unauthenticated attackers can take over WordPress accounts, including admin roles. Patching is essential.
August 13, 2026
CVE-2026-14922: WP Photo Album Plus < 9.2.04.003 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-14922 affects WP Photo Album Plus versions up to 9.2.04.003, posing a medium severity risk (CVSS 6.4) due to Stored Cross-Site Scripting. Users should upgrade to the patched version to mitigate this vulnerability.
August 13, 2026
CVE-2026-16810: Bit Form <= 3.2.0 Authenticated (Administrator+) SQL Injection via 'filterText' Parameter PoC, Patch Analysis & Rule
CVE-2026-16810 affects the Bit Form plugin (up to v3.2.0) with a medium severity SQL injection vulnerability (CVSS 6.5). Update to v3.2.1 to mitigate risks of data exposure by authenticated attackers.
August 13, 2026
CVE-2026-18109: W3 Total Cache <= 2.10.3 Unauthenticated Stored Cross-Site Scripting via Comment Author Name PoC, Patch Analysis & Rule
CVE-2026-18109 affects W3 Total Cache plugin versions up to 2.10.3 with a CVSS score of 7.2. This high-severity stored XSS vulnerability allows unauthenticated attackers to inject scripts. Upgrade to 2.10.4 to mitigate.
August 13, 2026
CVE-2026-73401: InstaWP Connect – 1-click WP Staging & Migration <= 0.1.3.7 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-73401 affects the InstaWP Connect plugin (up to v0.1.3.7) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Update to v0.1.3.8 to mitigate risks associated with unauthorized migration actions.
August 13, 2026
CVE-2026-13612: KiviCare – Clinic & Patient Management System (EHR) < 4.5.2 Authenticated (Custom role+) Information Exposure PoC, Patch Analysis & Rule
CVE-2026-13612 affects the Kivicare Clinic Management System plugin (up to version 4.5.2) with a CVSS score of 4.3. Authenticated attackers can access sensitive data; patching is essential to mitigate this risk.
August 13, 2026
CVE-2026-12976: LearnPress – WordPress LMS Plugin for Create and Sell Online Courses < 4.4.4 Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule
CVE-2026-12976 affects the LearnPress plugin (up to version 4.4.4) with a CVSS score of 4.3. Authenticated attackers can exploit this vulnerability to access sensitive data. Users should update to the patched version to mitigate risks.
August 13, 2026
CVE-2026-13168: Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.20 Authenticated (Contributor+) Information Exposure PoC, Patch Analysis & Rule
CVE-2026-13168 affects the Wp Event Solution plugin (up to version 4.1.20) with a medium severity (CVSS 4.3). Authenticated attackers can exploit this vulnerability to access sensitive user data. Users should update to the patched version.
August 13, 2026
CVE-2026-73349: GiveWP – Donation Plugin and Fundraising Platform < 4.16.6 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-73349 affects the GiveWP Donation Plugin (up to version 4.16.6) allowing unauthorized access due to a missing capability check. Users should patch to the latest version to mitigate this medium severity vulnerability.
August 13, 2026
CVE-2025-10308: Astro Booking Engine <= 1.4.0 Cross-Site Request Forgery to Settings Reset PoC, Patch Analysis & Rule
CVE-2025-10308 affects the Astro Booking Engine plugin (up to v1.4.0) with a medium severity (CVSS 4.3) CSRF vulnerability. Update to v1.4.1 to mitigate the risk of unauthorized settings deletion.
August 13, 2026
CVE-2026-13177: Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.20 Authenticated (Contributor+) Information Exposure PoC, Patch Analysis & Rule
CVE-2026-13177 affects the Wp Event Solution plugin (up to version 4.1.20) with a medium severity CVSS score of 4.3, allowing authenticated attackers to access sensitive data. Ensure you update to the patched version to mitigate this risk.
August 13, 2026
CVE-2026-66660: Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-66660 affects the Contact Form 7 Paypal Add On (up to version 2.5.1) with a medium severity (CVSS 5.3) vulnerability allowing unauthorized access. Users should update to the patched version to mitigate risks.
August 13, 2026
CVE-2026-73353: Revolut Gateway for WooCommerce < 4.22.10 Missing Authorization PoC, Patch Analysis & Rule
CVE-2026-73353 affects the Revolut Gateway for WooCommerce plugin, allowing unauthorized access due to a missing capability check. Users should update to version 4.22.10 to mitigate this medium severity vulnerability.
August 13, 2026
CVE-2026-73346: Mailchimp for WooCommerce < 6.2 Authenticated (Administrator+) SQL Injection PoC, Patch Analysis & Rule
CVE-2026-73346 affects the Mailchimp for WooCommerce plugin (up to version 6.2) with a medium severity SQL injection vulnerability. Admins should patch to the latest version to prevent potential data exposure.
August 13, 2026
CVE-2026-73357: GiveWP – Donation Plugin and Fundraising Platform < 4.16.6 Authenticated (Donor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
CVE-2026-73357 affects the GiveWP Donation Plugin for WordPress, allowing authenticated attackers to exploit a Stored XSS vulnerability. Users should update to version 4.16.6 to mitigate this medium severity risk with a CVSS score of 6.4.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
