Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

2026-02-14

CVE-2026-1750: Ecwid by Lightspeed Ecommerce Shopping Cart <= 7.0.7 – Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access (ecwid-shopping-cart)

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the 'save_custom_user_profile_fields' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to supply the 'ec_store_admin_access' parameter during…
2026-02-14

CVE-2026-1793: Element Pack Addons for Elementor <= 8.3.17 – Authenticated (Contributor+) Arbitrary File Read (bdthemes-element-pack-lite)

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the SVG widget and a lack of sufficient file validation in the 'render_svg' function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of…
2026-02-13

CVE-2026-1841: PixelYourSite <= 11.2.0 – Unauthenticated Stored Cross-Site Scripting (pixelyoursite)

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page' parameter in all versions up to, and including, 11.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
2026-02-13

CVE-2025-14608: WP Last Modified Info <= 1.9.5 – Insecure Direct Object Reference to Authenticated (Author+) Post Metadata Modification (wp-last-modified-info)

The WP Last Modified Info plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.5. This is due to the plugin not validating a user's access to a post before modifying its metadata in the 'bulk_save' AJAX action. This makes it possible for authenticated attackers, with Author-level…
2026-02-13

CVE-2026-1844: PixelYourSite PRO <= 12.4.0.2 – Unauthenticated Stored Cross-Site Scripting (pixelyoursite-pro)

The PixelYourSite PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page' parameter in all versions up to, and including, 12.4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a…
2026-02-13

CVE-2025-14067: Easy Form Builder <= 3.9.3 – Missing Authorization to Authenticated (Subscriber+) Sensitive Form Response Data Exposure (easy-form-builder)

The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive form response data, including messages, admin replies, and…
2026-02-13

CVE-2026-1164: Easy Voice Mail <= 1.2.5 – Unauthenticated Stored Cross-Site Scripting via 'message' (easy-voice-mail)

The Easy Voice Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute…
2026-02-13

CVE-2025-13681: BFG Tools – Extension Zipper <= 1.0.7 – Authenticated (Administrator+) Path Traversal via 'first_file' Parameter (bfg-tools-extension-zipper)

The BFG Tools – Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.7. This is due to insufficient input validation on the user-supplied `first_file` parameter in the `zip()` function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of…
2026-02-13

CVE-2026-1912: Citations tools <= 0.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'code' Shortcode Attribute (citations-tools)

The Citations tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in the 'ctdoi' shortcode in all versions up to, and including, 0.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary…
2026-02-13

CVE-2025-15157: Starfish Review Generation & Marketing for WordPress <= 3.1.19 – Authenticated (Subscriber+) Arbitrary Options Update via srm_restore_options_defaults (starfish-reviews)

The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'srm_restore_options_defaults' function in all versions up to, and including, 3.1.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works