Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

2026-03-02

CVE-2026-3180: Contest Gallery <= 28.1.4 – Unauthenticated SQL Injection (contest-gallery)

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to, and including, 28.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
2026-03-02

CVE-2026-1336: AI ChatBot with ChatGPT and Content Generator by AYS <= 2.7.5 – Missing Authorization to Unauthenticated API Key Modification (ays-chatgpt-assistant)

The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the store_data() and get_chatgpt_api_key() functions in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated attackers to view, modify or delete the plugin's…
2026-03-02

CVE-2026-1487: LatePoint <= 5.2.7 – Authenticated (Administrator+) SQL Injection via JSON Import (latepoint)

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to SQL Injection via the JSON Import in all versions up to, and including, 5.2.7 due to insufficient validation on the user-supplied JSON data. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary SQL…
2026-03-02

CVE-2026-1492: User Registration & Membership <= 5.1.2 – Unauthenticated Privilege Escalation via Membership Registration (user-registration)

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side…
2026-03-02

CVE-2026-2568: WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 – Unauthenticated Stored Cross-Site Scripting (cf7-zendesk)

The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission data in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
2026-02-27

CVE-2026-28101: UberSlider MouseInteraction <= 2.3 – Reflected Cross-Site Scripting (uberSlider_mouseinteraction)

The UberSlider MouseInteraction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such…
2026-02-27

CVE-2026-28099: UberSlider Ultra <= 2.3 – Reflected Cross-Site Scripting (uberSlider_ultra)

The UberSlider Ultra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such…
2026-02-27

CVE-2026-28100: UberSlider PerpetuumMobile <= 2.3 – Reflected Cross-Site Scripting (uberSlider_perpetuummobile)

The UberSlider PerpetuumMobile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such…
2026-02-27

CVE-2026-28102: UberSlider Classic <= 2.5 – Reflected Cross-Site Scripting (uberSlider_classic)

The UberSlider Classic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such…
2026-02-27

CVE-2026-2471: WP Mail Logging <= 1.15.0 – Unauthenticated PHP Object Injection via Email Log Message Field (wp-mail-logging)

The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of untrusted input from the email log message field. This is due to the `BaseModel` class constructor calling `maybe_unserialize()` on all properties retrieved from the database without validation. This makes it possible…
2026-02-27

CVE-2025-13673: Tutor LMS <= 3.9.6 – Unauthenticated SQL Injection via coupon_code (tutor)

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 3.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers…
2026-02-26

CVE-2026-1565: User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 – Authenticated (Author+) Arbitrary File Upload (wp-user-frontend)

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' function in all versions up to, and including, 4.2.8. This makes it possible for authenticated attackers, with Author-level…
2026-02-26

CVE-2026-28126: RH Frontend Publishing Pro <= 4.3.2 – Reflected Cross-Site Scripting (rh-frontend)

The RH Frontend Publishing Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an…
2026-02-26

CVE-2026-28114: WooCommerce License Manager <= 7.0.6 – Authenticated (Shop Manager+) Arbitrary File Upload (fs-license-manager)

The WooCommerce License Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 7.0.6. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution…
2026-02-26

CVE-2026-28103: Responsive Zoom In/Out Slider WordPress Plugin <= 5.4.5 – Reflected Cross-Site Scripting (lbg_zoominoutslider)

The Responsive Zoom In/Out Slider WordPress Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into…
2026-02-26

CVE-2026-28104: Site Suggest <= 1.3.9 – Missing Authorization (site-suggest)

The Site Suggest plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.3.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-02-26

CVE-2026-28110: LambertGroup – AllInOne – Banner with Playlist <= 3.8 – Reflected Cross-Site Scripting (all-in-one-bannerWithPlaylist)

The LambertGroup - AllInOne - Banner with Playlist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user…
2026-02-26

CVE-2026-28109: LambertGroup – AllInOne – Content Slider <= 3.8 – Reflected Cross-Site Scripting (all-in-one-contentSlider)

The LambertGroup - AllInOne - Content Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into…
2026-02-26

CVE-2026-28127: Lawyer Directory <= 1.3.2 – Unauthenticated Stored Cross-Site Scripting (lawyer-directory)

The Lawyer Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
2026-02-26

CVE-2026-28113: Ultimate Learning Pro <= 3.9.1 – Reflected Cross-Site Scripting (indeed-learning-pro)

The Ultimate Learning Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action…

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works