
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
April 6, 2026
CVE-2026-25462: avalex – Automatisch sichere Rechtstexte <= 3.1.3 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-25462 in Avalex (CVSS 5.3): avalex – Automatisch sichere Rechtstexte. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
April 6, 2026
CVE-2026-24987: Activity Log for WordPress <= 1.2.7 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24987 in Winterlock (CVSS 4.3): Activity Log for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.2.8.
April 6, 2026
CVE-2026-25309: Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors <= 4.10.1 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-25309 in Publishpress Authors (CVSS 5.3): Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
April 6, 2026
CVE-2026-25460: Ave Core <= 2.9.1 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-25460 in Ave Core (CVSS 4.3): Ave Core. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
April 6, 2026
CVE-2026-32586: Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools < 7.11.3 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-32586 in Woocommerce Jetpack (CVSS 5.3): Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools < 7.11.3 -.... Atomic Edge summarizes impact, exploitability, and patch details, with WAF...
April 6, 2026
CVE-2026-24983: UpSolution Core <= 8.41 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-24983 in Us Core (CVSS 6.1): UpSolution Core. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
April 6, 2026
CVE-2026-4347: MW WP Form <= 5.1.0 Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir PoC, Patch Analysis & Rule
High CVE-2026-4347 in Mw Wp Form (CVSS 8.1): MW WP Form. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.1.1.
April 6, 2026
CVE-2026-0688: Webmention <= 5.6.2 Authenticated (Subscriber+) Server-Side Request Forgery PoC, Patch Analysis & Rule
Medium CVE-2026-0688 in Webmention (CVSS 6.4): Webmention. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.7.0.
April 6, 2026
CVE-2026-32526: Abandoned Cart Recovery for WooCommerce <= 1.1.10 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2026-32526 in Woo Abandoned Cart Recovery (CVSS 7.2): Abandoned Cart Recovery for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
April 6, 2026
CVE-2026-5032: W3 Total Cache <= 2.9.3 Unauthenticated Security Token Exposure via User-Agent Header PoC, Patch Analysis & Rule
High CVE-2026-5032 in W3 Total Cache (CVSS 7.5): W3 Total Cache. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.9.4.
April 6, 2026
CVE-2026-0686: Webmention <= 5.6.2 Unauthenticated Blind Server-Side Request Forgery PoC, Patch Analysis & Rule
High CVE-2026-0686 in Webmention (CVSS 7.2): Webmention. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.7.0.
April 6, 2026
CVE-2026-32540: Online Scheduling and Appointment Booking System – Bookly <= 26.7 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-32540 in Bookly Responsive Appointment Booking Tool (CVSS 6.1): Online Scheduling and Appointment Booking System – Bookly. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage...
April 6, 2026
CVE-2026-32495: WP Terms Popup – Terms and Conditions and Privacy Policy WordPress Popups <= 2.10.0 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-32495 in Wp Terms Popup (CVSS 5.3): WP Terms Popup – Terms and Conditions and Privacy Policy WordPress Popups. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.11.0.
April 6, 2026
CVE-2026-3572: iTracker360 <= 2.2.0 Cross-Site Request Forgery to Stored Cross-Site Scripting via 'itracker_license' Settings Field PoC, Patch Analysis & Rule
Medium CVE-2026-3572 in Itracker360 (CVSS 6.1): iTracker360. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
April 6, 2026
CVE-2026-32530: Creator LMS – Online Courses and eLearning Plugin <= 1.1.18 Authenticated (Contributor+) Privilege Escalation PoC, Patch Analysis & Rule
High CVE-2026-32530 in Creatorlms (CVSS 8.8): Creator LMS – Online Courses and eLearning Plugin. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.1.19.
April 6, 2026
CVE-2026-32513: JS Archive List <= 6.1.7 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2026-32513 in Jquery Archive List Widget (CVSS 7.5): JS Archive List. Atomic Edge summarizes impact, exploitability, and patch details. Update to 6.2.0.
April 6, 2026
CVE-2026-32516: Miraculous Core < 2.1.2 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2026-32516 in Miraculouscore (CVSS 6.5): Miraculous Core < 2.1.2 - Authenticated (Subscriber+) SQL Injection. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
April 6, 2026
CVE-2026-32496: Spam Protect for Contact Form 7 <= 1.2.9 Authenticated (Editor+) Arbitrary File Deletion PoC, Patch Analysis & Rule
Medium CVE-2026-32496 in Wp Contact Form 7 Spam Blocker (CVSS 6.5): Spam Protect for Contact Form 7. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.2.10.
April 6, 2026
CVE-2026-32538: SMTP Mailer <= 1.1.24 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
High CVE-2026-32538 in Smtp Mailer (CVSS 7.5): SMTP Mailer. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
April 6, 2026
CVE-2026-32527: WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-32527 in Cf7 Insightly (CVSS 4.3): WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.1.6.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
