
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
2026-02-13
CVE-2026-0550: myCred <= 2.9.7.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'mycred_load_coupon' Shortcode (mycred)
The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mycred_load_coupon' shortcode in all versions up to, and including, 2.9.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in…
2026-02-13
CVE-2025-15483: Link Hopper <= 2.5 – Authenticated (Administrator+) Stored Cross-Site Scripting via 'hop_name' Parameter (link-hopper)
The Link Hopper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hop_name’ parameter in all versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user…
2026-02-13
CVE-2026-1254: Modula Image Gallery – Photo Grid & Video Gallery <= 2.13.6 – Missing Authorization to Authenticated (Contributor+) Arbitrary Post/Page Editing (modula-best-grid-gallery)
The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly verifying that a user is authorized to modify specific posts before updating them via the REST API. This makes it possible…
2026-02-13
CVE-2025-8572: Truelysell Core <= 1.8.7 – Unauthenticated Privilege Escalation via Registration (truelysell-core)
The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated privileges, including administrator access.
2026-02-13
CVE-2026-1843: Super Page Cache <= 5.2.2 – Unauthenticated Stored Cross-Site Scripting via Activity Log (wp-cloudflare-page-cache)
The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an…
2026-02-13
CVE-2026-1249: MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 5.3 – 5.10 – Authenticated (Author+) Server-Side Request Forgery (mp3-music-player-by-sonaar)
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 5.3 to 5.10 via the 'load_lyrics_ajax_callback' function. This makes it possible for authenticated attackers, with author level access and above, to make web requests to arbitrary locations originating from the web…
2026-02-13
CVE-2026-2312: Media Library Folders <= 8.3.6 – Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Attachment Deletion and Rename (media-library-plus)
The Media Library Folders plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 8.3.6 via the delete_maxgalleria_media() and maxgalleria_rename_image() functions due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to delete or rename attachments owned…
2026-02-13
CVE-2026-1512: Essential Addons for Elementor <= 6.5.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget (essential-addons-for-elementor-lite)
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, and including, 6.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level…
2026-02-12
CVE-2026-25036: Passster <= 4.2.25 – Missing Authorization (content-protector)
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
2026-02-12
CVE-2026-1316: Customer Reviews for WooCommerce <= 5.97.0 – Unauthenticated Stored Cross-Site Scripting via media[].href Parameter (customer-reviews-woocommerce)
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].href' parameter in all versions up to, and including, 5.97.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers (if 'Enable for Guests' is enabled) to inject arbitrary web scripts in pages that…
2026-02-12
CVE-2026-1320: Secure Copy Content Protection and Content Locking <= 4.9.8 – Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header (secure-copy-content-protection)
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' HTTP header in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
2026-02-11
CVE-2026-22345: Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery <= 1.6.0 – Authenticated (Contributor+) PHP Object Injection (new-image-gallery)
The Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present…
2026-02-11
CVE-2025-68526: Modal Popup Box <= 1.6.1 – Authenticated (Contributor+) PHP Object Injection (modal-popup-box)
The Modal Popup Box plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP…
2026-02-11
CVE-2025-69403: Bravis Addons <= 1.1.9 – Authenticated (Subscriber+) Arbitrary File Upload (bravis-addons)
The Bravis Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
2026-02-11
CVE-2025-69392: iMoney <= 0.36 – Reflected Cross-Site Scripting (imoney)
The iMoney plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.36 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as…
2026-02-11
CVE-2025-69401: WooODT Lite <= 2.5.2 – Unauthenticated Payment Bypass (byconsole-woo-order-delivery-time)
The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to bypass payments for orders.
2026-02-11
CVE-2026-1104: FastDup – Fastest WordPress Migration & Duplicator <= 2.7.1 – Missing Authorization to Authenticated (Contributor+) Backup Creation and Download (fastdup)
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to create and download full-site backup…
2026-02-11
CVE-2026-22346: Slider Responsive Slideshow – Image slider, Gallery slideshow <= 1.5.4 – Authenticated (Contributor+) PHP Object Injection (slider-responsive-slideshow)
The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.4 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the…
2026-02-11
CVE-2026-24956: Download Manager Addons for Elementor <= 1.3.0 – Unauthenticated SQL Injection (wpdm-elementor)
The Download Manager Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing…
2026-02-11
CVE-2025-15400: OpenPix <= 2.13.3 – Missing Authorization to Authenticated (Subscriber+) Settings Update (openpix-for-woocommerce)
The OpenPix for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.13.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
