Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

April 19, 2026

CVE-2026-0811: Advanced CF7 DB <= 2.0.9 Cross-Site Request Forgery to Form Entry Deletion PoC, Patch Analysis & Rule

Medium CVE-2026-0811 in Advanced Cf7 Db (CVSS 5.4): Advanced CF7 DB. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.0.
April 19, 2026

CVE-2026-39524: Masteriyo LMS – Online Course Builder for eLearning, LMS & Education <= 2.1.5 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-39524 in Learning Management System (CVSS 5.3): Masteriyo LMS – Online Course Builder for eLearning, LMS & Education. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.1.6.
April 19, 2026

CVE-2026-39480: BackupBliss – Backup & Migration with Free Cloud Storage <= 2.1.1 Unauthenticated Information Exposure PoC, Patch Analysis & Rule

Medium CVE-2026-39480 in Backup Backup (CVSS 5.3): BackupBliss – Backup & Migration with Free Cloud Storage. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.2.
April 19, 2026

CVE-2026-0814: Advanced CF7 DB <= 2.0.9 Missing Authorization to Authenticated (Subscriber+) Form Submissions Excel Export PoC, Patch Analysis & Rule

Medium CVE-2026-0814 in Advanced Cf7 Db (CVSS 4.3): Advanced CF7 DB. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.0.
April 19, 2026

CVE-2026-39502: Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.38 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-39502 in Form Maker (CVSS 7.5): Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.15.39.
April 19, 2026

CVE-2026-39534: WP Directory Kit <= 1.5.0 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-39534 in Wpdirectorykit (CVSS 5.3): WP Directory Kit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
April 19, 2026

CVE-2025-15611: Popup Box – Create Countdown, Coupon, Video, Contact Form Popups < 5.5.0 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule

High CVE-2025-15611 in Ays Popup Box (CVSS 7.2): Popup Box – Create Countdown, Coupon, Video, Contact Form Popups < 5.5.0 - Unauthenticated Stored.... Atomic Edge summarizes impact, exploitability, and patch details. Update to 5.5.0.
April 19, 2026

CVE-2026-3568: MStore API <= 4.18.3 Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update PoC, Patch Analysis & Rule

Medium CVE-2026-3568 in Mstore Api (CVSS 4.3): MStore API. Atomic Edge summarizes impact, exploitability, and patch details. Update to 4.18.4.
April 19, 2026

CVE-2026-39492: WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-39492 in Wp Google Map Plugin (CVSS 7.5): WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage...
April 19, 2026

CVE-2026-39493: Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.27 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-39493 in Simply Schedule Appointments (CVSS 7.5): Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage...
April 19, 2026

CVE-2026-39533: AWP Classifieds <= 4.4.4 Missing Authorization PoC, Patch Analysis & Rule

High CVE-2026-39533 in Another Wordpress Classifieds Plugin (CVSS 7.5): AWP Classifieds. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.4.5.
April 19, 2026

CVE-2026-4429: OSM <= 6.1.15 Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker_name' Shortcode Attribute PoC, Patch Analysis & Rule

Medium CVE-2026-4429 in Osm (CVSS 6.4): OSM. Atomic Edge summarizes impact, exploitability, and patch details. Update to 6.1.16.
April 19, 2026

CVE-2026-4079: SQL Chart Builder < 2.3.8 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-4079 in Sql Chart Builder (CVSS 7.5): SQL Chart Builder < 2.3.8 - Unauthenticated SQL Injection. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.3.8.
April 19, 2026

CVE-2026-4124: Ziggeo <= 3.1.1 Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'ziggeo_ajax' AJAX Action PoC, Patch Analysis & Rule

Medium CVE-2026-4124 in Ziggeo (CVSS 5.4): Ziggeo. Atomic Edge summarizes impact, exploitability, and patch details.
April 19, 2026

CVE-2026-3005: List category posts <= 0.94.0 Authenticated (Author+) Stored Cross-Site Scripting via 'catlist' Shortcode PoC, Patch Analysis & Rule

Medium CVE-2026-3005 in List Category Posts (CVSS 6.4): List category posts. Atomic Edge summarizes impact, exploitability, and patch details. Update to 0.95.0.
April 19, 2026

CVE-2026-4326: Vertex Addons for Elementor <= 1.6.4 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation via 'afeb_activate_required_plugins' PoC, Patch Analysis & Rule

High CVE-2026-4326 in Addons For Elementor Builder (CVSS 8.8): Vertex Addons for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.7.0.
April 19, 2026

CVE-2026-39587: WP BASE Booking of Appointments, Services and Events <= 5.9.0 Unauthenticated Privilege Escalation PoC, Patch Analysis & Rule

Critical CVE-2026-39587 in Wp Base Booking Of Appointments Services And Events (CVSS 9.8): WP BASE Booking of Appointments, Services and Events. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage...
April 19, 2026

CVE-2026-39591: WP-BusinessDirectory – Business directory plugin for WordPress <= 4.0.0 Authenticated (Subscriber+) Arbitrary File Upload PoC, Patch Analysis & Rule

High CVE-2026-39591 in Wp Businessdirectory (CVSS 8.8): WP-BusinessDirectory – Business directory plugin for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
April 19, 2026

CVE-2026-39519: GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content <= 1.2.0 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2026-39519 in Geeky Bot (CVSS 7.5): GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.2.1.
April 18, 2026

CVE-2026-5226: Optimole <= 4.2.3 Reflected Cross-Site Scripting via Page Profiler URL PoC, Patch Analysis & Rule

Medium CVE-2026-5226 in Optimole Wp (CVSS 6.1): Optimole. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.2.4.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works