
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
2026-02-12
CVE-2026-1320: Secure Copy Content Protection and Content Locking <= 4.9.8 – Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header (secure-copy-content-protection)
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' HTTP header in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
2026-02-11
CVE-2026-22345: Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery <= 1.6.0 – Authenticated (Contributor+) PHP Object Injection (new-image-gallery)
The Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present…
2026-02-11
CVE-2025-68526: Modal Popup Box <= 1.6.1 – Authenticated (Contributor+) PHP Object Injection (modal-popup-box)
The Modal Popup Box plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP…
2026-02-11
CVE-2025-69403: Bravis Addons <= 1.1.9 – Authenticated (Subscriber+) Arbitrary File Upload (bravis-addons)
The Bravis Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
2026-02-11
CVE-2025-69392: iMoney <= 0.36 – Reflected Cross-Site Scripting (imoney)
The iMoney plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.36 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as…
2026-02-11
CVE-2025-69401: WooODT Lite <= 2.5.2 – Unauthenticated Payment Bypass (byconsole-woo-order-delivery-time)
The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to bypass payments for orders.
2026-02-11
CVE-2026-1104: FastDup – Fastest WordPress Migration & Duplicator <= 2.7.1 – Missing Authorization to Authenticated (Contributor+) Backup Creation and Download (fastdup)
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and download full-site backup…
2026-02-11
CVE-2026-22346: Slider Responsive Slideshow – Image slider, Gallery slideshow <= 1.5.4 – Authenticated (Contributor+) PHP Object Injection (slider-responsive-slideshow)
The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.4 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the…
2026-02-11
CVE-2026-24956: Download Manager Addons for Elementor <= 1.3.0 – Unauthenticated SQL Injection (wpdm-elementor)
The Download Manager Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing…
2026-02-11
CVE-2025-15400: OpenPix <= 2.13.3 – Missing Authorization to Authenticated (Subscriber+) Settings Update (openpix-for-woocommerce)
The OpenPix for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.13.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
