
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
2026-03-18
CVE-2026-25429: Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 1.1.1 – Unauthenticated PHP Object Injection (nexa-blocks)
The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable…
2026-03-18
CVE-2026-24362: Ultimate Post Kit Addons for Elementor <= 4.0.21 – Missing Authorization (ultimate-post-kit)
The Ultimate Post Kit Addons for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.21. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
2026-03-18
CVE-2026-25317: Print Invoice & Delivery Notes for WooCommerce <= 5.9.0 – Missing Authorization (woocommerce-delivery-notes)
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.9.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-18
CVE-2026-24989: SUMO Affiliates Pro < 11.4.0 – Unauthenticated PHP Object Injection (affs)
The SUMO Affiliates Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to 11.4.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin…
2026-03-18
CVE-2026-25013: Phox Hosting <= 2.0.8 – Reflected Cross-Site Scripting (phox-host)
The Phox Hosting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such…
2026-03-18
CVE-2026-25430: Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.2.2 – Missing Authorization (cf7-mailchimp)
The Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
2026-03-18
CVE-2026-32565: Contextual Related Posts < 4.2.2 – Missing Authorization (contextual-related-posts)
The Contextual Related Posts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 4.2.2 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-18
CVE-2026-25446: Wishlist Member <= 3.29.0 – Authenticated (Subscriber+) Arbitrary File Upload (wishlist-member-x)
The Wishlist Member plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.29.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
2026-03-18
CVE-2026-24376: WPVulnerability <= 4.2.1 – Missing Authorization (wpvulnerability)
The WPVulnerability plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
2026-03-18
CVE-2026-25438: Gutenberg Blocks – Unlimited blocks For Gutenberg <= 1.2.8 – Reflected Cross-Site Scripting (unlimited-blocks)
The Gutenberg Blocks – Unlimited blocks For Gutenberg plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user…
2026-03-18
CVE-2026-25445: Wishlist Member <= 3.29.0 – Authenticated (Subscriber+) PHP Object Injection (wishlist-member-x)
The Wishlist Member plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.29.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain…
2026-03-18
CVE-2026-25312: EventPrime – Events Calendar, Bookings and Tickets <= 4.2.8.3 – Missing Authorization (eventprime-event-calendar-management)
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.8.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-18
CVE-2026-25435: Booking calendar, Appointment Booking System <= 3.2.36 – Unauthenticated Stored Cross-Site Scripting (booking-calendar)
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
2026-03-18
CVE-2026-25443: Fraud Prevention For WooCommerce and EDD <= 2.3.3 – Missing Authorization to Unauthenticated Arbitrary Content Deletion (woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers)
The Fraud Prevention For WooCommerce and EDD plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-17
CVE-2026-2992: KiviCare <= 4.1.2 – Missing Authorization to Unauthenticated Privilege Escalation via Setup Wizard (kivicare-clinic-management-system)
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to create a new clinic and a WordPress user with clinic admin privileges.
2026-03-17
CVE-2026-2991: KiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 – Unauthenticated Authentication Bypass via Social Login Token (kivicare-clinic-management-system)
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social provider access token before authenticating a user. This makes it possible for unauthenticated attackers to log in as any…
2026-03-17
CVE-2026-1463: Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 4.0.4 – Authenticated (Author+) Local File Inclusion (nextgen-gallery)
The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter in gallery shortcodes. This makes it possible for authenticated attackers, with Author-level access and above, to include and execute arbitrary .php files on the…
2026-03-17
CVE-2026-2512: Code Embed <= 2.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields (simple-embed-code)
The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all versions up to, and including, 2.5.1. This is due to the plugin's sanitization function `sec_check_post_fields()` only running on the `save_post` hook, while WordPress allows custom fields to be added via the `wp_ajax_add_meta` AJAX endpoint without triggering…
2026-03-17
CVE-2026-1780: [CR]Paid Link Manager <= 0.5 – Reflected Cross-Site Scripting (crpaid-link-manager)
The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up to, and including, 0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a…
2026-03-17
CVE-2026-1217: Yoast Duplicate Post <= 4.5 – Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite (duplicate-post)
The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private,…
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
