
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
2026-03-17
CVE-2026-4268: WP Go Maps (formerly WP Google Maps) <= 10.0.05 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings (wp-google-maps)
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_custom_js’ parameter in all versions up to, and including, 10.0.05 due to insufficient input sanitization and output escaping and missing capability check in the 'admin_post_wpgmza_save_settings' hook anonymous function. This makes it possible for authenticated attackers, with…
2026-03-17
CVE-2026-3512: Writeprint Stylometry <= 0.1 – Reflected Cross-Site Scripting via 'p' Parameter (writeprint-stylometry)
The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter in all versions up to and including 0.1. This is due to insufficient input sanitization and output escaping in the bjl_wprintstylo_comments_nav() function. The function directly outputs the $_GET['p'] parameter into an HTML href attribute without any escaping. This…
2026-03-17
CVE-2026-1926: Subscriptions for WooCommerce <= 1.9.2 – Missing Authorization to Unauthenticated Arbitrary Subscription Cancellation (subscriptions-for-woocommerce)
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wps_sfw_admin_cancel_susbcription()` function in all versions up to, and including, 1.9.2. This is due to the function being hooked to the `init` action without any authentication or authorization checks, and only performing a non-empty…
2026-03-17
CVE-2026-3090: Post SMTP <= 3.8.0 – Unauthenticated Stored Cross-Site Scripting via 'event_type' (post-smtp)
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_type’ parameter in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
2026-03-17
CVE-2026-25456: Automated FedEx live/manual rates with shipping labels – HPOS supported <= 5.1.8 – Missing Authorization (a2z-fedex-shipping)
The Automated FedEx live/manual rates with shipping labels – HPOS supported plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-17
CVE-2026-25461: Listeo-Core – Directory Plugin by Purethemes <= 2.0.21 – Reflected Cross-Site Scripting (listeo-core)
The Listeo-Core - Directory Plugin by Purethemes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into…
2026-03-17
CVE-2026-25452: Remoji – Post/Comment Reaction and Enhancement <= 2.2 – Unauthenticated Stored Cross-Site Scripting (remoji)
The Remoji – Post/Comment Reaction and Enhancement plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
2026-03-17
CVE-2026-25465: CP Multi View Events Calendar <= 1.4.34 – Authenticated (Subscriber+) Stored Cross-Site Scripting (cp-multi-view-calendar)
The CP Multi View Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user…
2026-03-17
CVE-2026-25455: Product Slider, Product Grid, Product Masonry <= 1.13.60 – Missing Authorization (woocommerce-products-slider)
The Product Slider, Product Grid, Product Masonry plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.13.60. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
2026-03-17
CVE-2026-24983: UpSolution Core <= 8.41 – Reflected Cross-Site Scripting (us-core)
The UpSolution Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 8.41 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such…
2026-03-17
CVE-2026-32586: Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools < 7.11.3 – Missing Authorization (woocommerce-jetpack)
The Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 7.11.3 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-17
CVE-2026-25460: Ave Core <= 2.9.1 – Missing Authorization (ave-core)
The Ave Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
2026-03-17
CVE-2026-25309: Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors <= 4.10.1 – Missing Authorization (publishpress-authors)
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.10.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-17
CVE-2026-24987: Activity Log for WordPress <= 1.2.7 – Missing Authorization (winterlock)
The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
2026-03-17
CVE-2026-25462: avalex – Automatisch sichere Rechtstexte <= 3.1.3 – Missing Authorization (avalex)
The avalex – Automatisch sichere Rechtstexte plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-03-17
CVE-2026-24378: EventPrime – Events Calendar, Bookings and Tickets <= 4.2.8.0 – Unauthenticated PHP Object Injection (eventprime-event-calendar-management)
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.8.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain…
2026-03-17
CVE-2026-25306: XStore Core <= 5.6.4 – Reflected Cross-Site Scripting (et-core-plugin)
The XStore Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.6.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such…
2026-03-16
CVE-2026-2373: Royal Addons for Elementor – Addons and Templates Kit for Elementor <= 1.7.1049 – Missing Authorization to Unauthenticated Custom Post Type Contents Exposure (royal-elementor-addons)
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1049 via the get_main_query_args() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract contents of non-public custom…
2026-03-16
CVE-2026-27046: StoreCustomizer – A plugin to Customize all WooCommerce Pages <= 2.6.3 – Missing Authorization (woocustomizer)
The StoreCustomizer – A plugin to Customize all WooCommerce Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
2026-03-16
CVE-2026-25369: Flexmls® IDX Plugin <= 3.15.9 – Reflected Cross-Site Scripting (flexmls-idx)
The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.15.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action…
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
