
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 30, 2026
CVE-2026-32536: Green Downloads <= 2.08 Authenticated (Subscriber+) Arbitrary File Upload PoC, Patch Analysis & Rule
High CVE-2026-32536 in Halfdata Paypal Green Downloads (CVSS 8.8): Green Downloads. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 30, 2026
CVE-2026-32521: WP Custom Admin Interface <= 7.42 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-32521 in Wp Custom Admin Interface (CVSS 6.4): WP Custom Admin Interface. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 7.43.
March 30, 2026
CVE-2026-25390: New User Approve <= 3.2.3 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-25390 in New User Approve (CVSS 4.3): New User Approve. Atomic Edge summarizes impact, exploitability, and patch details.
March 30, 2026
CVE-2026-32492: My Tickets – Accessible Event Ticketing <= 2.1.1 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-32492 in My Tickets (CVSS 5.3): My Tickets – Accessible Event Ticketing. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.2.
March 30, 2026
CVE-2026-32441: Comments Import & Export <= 2.4.9 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-32441 in Comments Import Export Woocommerce (CVSS 4.3): Comments Import & Export. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.5.0.
March 30, 2026
CVE-2026-32523: WPJAM Basic <= 6.9.2 Authenticated (Subscriber+) Arbitrary File Upload PoC, Patch Analysis & Rule
High CVE-2026-32523 in Wpjam Basic (CVSS 8.8): WPJAM Basic. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 30, 2026
CVE-2026-32534: JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.3 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2026-32534 in Js Support Ticket (CVSS 6.5): JS Help Desk – AI-Powered Support & Ticketing System. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.0.4.
March 29, 2026
CVE-2026-3124: Download Monitor <= 5.1.7 Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' PoC, Patch Analysis & Rule
High CVE-2026-3124 in Download Monitor (CVSS 7.5): Download Monitor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.1.8.
March 29, 2026
CVE-2026-2375: App Builder – Create Native Android & iOS Apps On The Flight <= 5.5.10 Unauthenticated Privilege Escalation via 'role' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-2375 in App Builder (CVSS 6.5): App Builder – Create Native Android & iOS Apps On The Flight. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 29, 2026
CVE-2026-4077: Ecover Builder For Dummies <= 1.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-4077 in Ecover Builder For Dummies (CVSS 6.4): Ecover Builder For Dummies. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 29, 2026
CVE-2026-4067: Ad Short <= 2.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'client' Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-4067 in Ad Short (CVSS 6.4): Ad Short. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 29, 2026
CVE-2026-4084: fyyd podcast shortcodes <= 0.3.1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-4084 in Fyyd Podcast Shortcodes (CVSS 6.4): fyyd podcast shortcodes. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 29, 2026
CVE-2026-4086: WP Random Button <= 1.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'cat' Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-4086 in Wp Random Button (CVSS 6.4): WP Random Button. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 29, 2026
CVE-2026-4022: Show Posts list <= 1.1.0 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode PoC, Patch Analysis & Rule
Medium CVE-2026-4022 in Show Posts Shortcodes (CVSS 6.4): Show Posts list. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 29, 2026
CVE-2026-2468: Quentn WP <= 1.2.12 Unauthenticated SQL Injection via 'qntn_wp_access' Cookie PoC, Patch Analysis & Rule
High CVE-2026-2468 in Quentn Wp (CVSS 7.5): Quentn WP. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 29, 2026
CVE-2026-3003: Vagaro Booking Widget <= 0.3 Unauthenticated Stored Cross-Site Scripting via 'vagaro_code' PoC, Patch Analysis & Rule
High CVE-2026-3003 in Vagaro Booking Widget (CVSS 7.2): Vagaro Booking Widget. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 29, 2026
CVE-2026-3506: WP-Chatbot for Messenger <= 4.9 Missing Authorization to Unauthenticated Chatbot Configuration Takeover PoC, Patch Analysis & Rule
Medium CVE-2026-3506 in Wp Chatbot (CVSS 5.3): WP-Chatbot for Messenger. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 29, 2026
CVE-2026-4087: Pre* Party Resource Hints <= 1.8.20 Authenticated (Subscriber+) SQL Injection via 'hint_ids' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-4087 in Pre Party Browser Hints (CVSS 6.5): Pre* Party Resource Hints. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 29, 2026
CVE-2026-2941: Linksy Search and Replace <= 1.0.4 Missing Authorization to Authenticated (Subscriber+) Arbitrary Database Update via linksy_search_and_replace_item_details PoC, Patch Analysis & Rule
High CVE-2026-2941 in Linksy Search And Replace (CVSS 8.8): Linksy Search and Replace. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 29, 2026
CVE-2026-3474: EmailKit <= 1.6.3 Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-3474 in Emailkit (CVSS 4.9): EmailKit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.6.4.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
