Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

2026-03-20

CVE-2026-32540: Online Scheduling and Appointment Booking System – Bookly <= 26.7 – Reflected Cross-Site Scripting (bookly-responsive-appointment-booking-tool)

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 26.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a…
2026-03-20

CVE-2026-32526: Abandoned Cart Recovery for WooCommerce <= 1.1.10 – Unauthenticated Stored Cross-Site Scripting (woo-abandoned-cart-recovery)

The Abandoned Cart Recovery for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
2026-03-20

CVE-2026-25365: Kargo Takip < 0.2.4 – Missing Authorization (kargo-takip-turkiye)

The Kargo Takip plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 0.2.4 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
2026-03-20

CVE-2026-32545: Taboola Pixel <= 1.1.4 – Reflected Cross-Site Scripting (taboola-pixel)

The Taboola Pixel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such…
2026-03-19

CVE-2026-4038: Aimogen Pro <= 2.7.5 – Unauthenticated Privilege Escalation via Arbitrary Function Call (aimogen-pro)

The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to call arbitrary WordPress functions such as 'update_option' to update the default…
2026-03-19

CVE-2026-3550: RockPress <= 1.0.17 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via AJAX Actions (ft-rockpress)

The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. This is due to missing capability checks on multiple AJAX actions (rockpress_import, rockpress_import_status, rockpress_last_import, rockpress_reset_import, and rockpress_check_services) combined with the plugin's nonce being exposed to all authenticated users via an unconditionally enqueued admin script. The plugin enqueues…
2026-03-19

CVE-2025-15363: Get Use APIs – JSON Content Importer < 2.0.10 – Authenticated (Contributor+) Stored Cross-Site Scripting (json-content-importer)

The Get Use APIs – JSON Content Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.0.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user…
2026-03-19

CVE-2026-4136: Membership Plugin – Restrict Content <= 3.2.24 – Unvalidated Redirect in Password Reset Flow via rcp_redirect (restrict-content)

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.2.24. This is due to insufficient validation on the redirect url supplied via the 'rcp_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the password reset email to potentially malicious…
2026-03-19

CVE-2026-2432: CM Custom Reports <= 1.2.7 – Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Labels (cm-custom-reports)

The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary…
2026-03-19

CVE-2026-2421: ilGhera Carta Docente for WooCommerce <= 1.5.0 – Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'cert' Parameter (wc-carta-docente)

The ilGhera Carta Docente for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the 'cert' parameter of the 'wccd-delete-certificate' AJAX action. This is due to insufficient file path validation before performing a file deletion. This makes it possible for authenticated attackers, with Administrator-level access and…
2026-03-18

CVE-2026-1238: SlimStat Analytics <= 5.3.5 – Unauthenticated Stored Cross-Site Scripting via 'fh' (wp-slimstat)

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) parameter in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an…
2026-03-18

CVE-2026-4068: Add Custom Fields to Media <= 2.0.3 – Cross-Site Request Forgery to Custom Field Deletion via 'delete' Parameter (add-custom-fields-to-media)

The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.3. This is due to missing nonce validation on the field deletion functionality in the admin display template. The plugin properly validates a nonce for the 'add field' operation (line 24-36), but the…
2026-03-18

CVE-2026-4120: Info Cards <= 2.0.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes (info-cards)

The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btnUrl' parameter within the Info Cards block in all versions up to, and including, 2.0.7. This is due to insufficient input validation on URL schemes, specifically the lack of javascript: protocol filtering. The…
2026-03-18

CVE-2026-4006: Draft List <= 2.6.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'display_name' Parameter (simple-draft-list)

The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta (Custom Field) in all versions up to and including 2.6.2. This is due to insufficient input sanitization and output escaping on the author display name when no author URL is present. The plugin accesses `$draft_data->display_name` which, because…
2026-03-18

CVE-2026-3475: Instant Popup Builder <= 1.1.7 – Unauthenticated Arbitrary Shortcode Execution via 'token' Parameter (instant-popup-builder)

The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all versions up to and including 1.1.7. This is due to the handle_email_verification_page() function constructing a shortcode string from user-supplied GET parameters (token, email) and passing it to do_shortcode() without properly sanitizing square bracket characters, combined with missing authorization checks…
2026-03-18

CVE-2026-2571: Download Manager <= 3.3.49 – Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter (download-manager)

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive information for any user on the site including email…
2026-03-18

CVE-2026-3658: Appointment Booking Calendar <= 1.6.10.0 – Unauthenticated SQL Injection via 'fields' Parameter (simply-schedule-appointments)

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in all versions up to, and including, 1.6.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated…
2026-03-18

CVE-2026-25437: GZSEO <= 2.0.14 – Missing Authorization (gzseo)

The GZSEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.14. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-18

CVE-2026-24993: Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting <= 4.1.3 – Unauthenticated SQL Injection (webd-woocommerce-advanced-reporting-statistics)

The Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to…
2026-03-18

CVE-2026-25447: Widget Wrangler <= 2.3.9 – Authenticated (Author+) Remote Code Execution (widget-wrangler)

The Widget Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.3.9. This makes it possible for authenticated attackers, with Author-level access and above, to execute code on the server.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works