
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
July 6, 2026
CVE-2026-9710: Cornerstone < 7.8.8 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-9710 in Cornerstone (CVSS 4.3): Cornerstone < 7.8.8 - Missing Authorization. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
July 6, 2026
CVE-2026-56053: EventPrime – Events Calendar, Bookings and Tickets <= 4.3.4.1 Authenticated (Subscriber+) PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-56053 in Eventprime Event Calendar Management (CVSS 7.5): EventPrime – Events Calendar, Bookings and Tickets. Atomic Edge summarizes impact, exploitability, and patch details. Update to 4.3.4.2.
July 5, 2026
CVE-2026-57652: JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.0 Unauthenticated Insecure Direct Object Reference PoC, Patch Analysis & Rule
Medium CVE-2026-57652 in Js Support Ticket (CVSS 5.3): JS Help Desk – AI-Powered Support & Ticketing System. Atomic Edge summarizes impact, exploitability, and patch details. Update to 3.1.1.
July 5, 2026
CVE-2025-68052: Eagle Booking <= 1.3.4.3 Cross-Site Request Forgery PoC, Patch Analysis & Rule
Medium CVE-2025-68052 in Eagle Booking (CVSS 4.3): Eagle Booking. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
July 5, 2026
CVE-2026-57648: Nelio Content – Editorial Calendar & Social Media Auto-Posting <= 4.3.4 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-57648 in Nelio Content (CVSS 4.3): Nelio Content – Editorial Calendar & Social Media Auto-Posting. Atomic Edge summarizes impact, exploitability, and patch details. Update to 4.3.5.
July 5, 2026
CVE-2026-57321: Interactive Content – H5P <= 1.17.7 Authenticated (Contributor+) Arbitrary File Deletion PoC, Patch Analysis & Rule
High CVE-2026-57321 in H5p (CVSS 8.1): Interactive Content – H5P. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.17.8.
July 5, 2026
CVE-2026-57627: Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.0.11 Authenticated (Subscriber+) Server-Side Request Forgery PoC, Patch Analysis & Rule
Medium CVE-2026-57627 in Kirki (CVSS 6.4): Kirki – Freeform Page Builder, Website Builder & Customizer. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 6.0.12.
July 5, 2026
CVE-2026-57649: Shoppable Images (Lookbook) for WooCommerce <= 1.3 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-57649 in Mabel Shoppable Images Lite (CVSS 4.3): Shoppable Images (Lookbook) for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.3.1.
July 5, 2026
CVE-2026-57314: SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments <= 4.3.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-57314 in Surecart (CVSS 6.1): SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions.... Atomic Edge summarizes impact, exploitability, and patch details. Update to 4.3.3.
July 5, 2026
CVE-2026-57640: MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.30 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-57640 in Masterstudy Lms Learning Management System (CVSS 4.3): MasterStudy LMS WordPress Plugin – for Online Courses and Education. Atomic Edge summarizes impact, exploitability, and patch details. Update to 3.7.31.
July 5, 2026
CVE-2025-63041: Forget About Shortcode Buttons <= 2.1.3 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-63041 in Forget About Shortcode Buttons (CVSS 4.3): Forget About Shortcode Buttons. Atomic Edge summarizes impact, exploitability, and patch details.
July 5, 2026
CVE-2026-57620: Exclusive Addons for Elementor <= 2.7.9.8 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-57620 in Exclusive Addons For Elementor (CVSS 6.4): Exclusive Addons for Elementor. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.7.9.9.
July 5, 2026
CVE-2026-57630: Blocksy Companion Pro <= 2.1.46 Unauthenticated Insecure Direct Object Reference PoC, Patch Analysis & Rule
Medium CVE-2026-57630 in Blocksy Companion Pro (CVSS 5.3): Blocksy Companion Pro. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
July 5, 2026
CVE-2026-57629: StatCounter – Free Real Time Visitor Stats <= 2.1.1 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-57629 in Official Statcounter Plugin For Wordpress (CVSS 6.4): StatCounter – Free Real Time Visitor Stats. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.1.2.
July 5, 2026
CVE-2026-57638: Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution <= 2.1.0 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-57638 in Fluent Booking (CVSS 6.4): Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
July 5, 2026
CVE-2026-57650: Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.8.3 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-57650 in Magazine Blocks (CVSS 6.4): Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts.... Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
July 5, 2026
CVE-2026-57654: Affiliates Manager <= 2.9.49 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-57654 in Affiliates Manager (CVSS 4.3): Affiliates Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
July 5, 2026
CVE-2026-57633: WCBoost – Products Compare <= 1.1.0 Unauthenticated Sensitive Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2026-57633 in Wcboost Products Compare (CVSS 5.3): WCBoost – Products Compare. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.1.1.
July 5, 2026
CVE-2026-57647: Panorama – 360 degree Virtual Tour, Panoramic Image viewer and More <= 1.6.1 Authenticated (Contributor+) Local File Inclusion PoC, Patch Analysis & Rule
High CVE-2026-57647 in Panorama (CVSS 7.5): Panorama – 360 degree Virtual Tour, Panoramic Image viewer and More. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.7.0.
July 5, 2026
CVE-2026-57642: Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress <= 4.7.8 Authenticated (Contributor+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2026-57642 in Gallery Plugin (CVSS 6.5): Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.7.9.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
