Atomic Edge Product

AI-Powered CVE Analysis for WordPress Plugins

We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.

WordPress Proof of Concepts

AI-assisted vulnerability analysis with PoC demonstration

March 23, 2026

CVE-2026-0939: Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.2 Unauthenticated Order Status Manipulation PoC, Patch Analysis & Rule

Medium CVE-2026-0939 in Woo Rede (CVSS 5.3): Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.1.3.
March 23, 2026

CVE-2025-14793: DK PDF – WordPress PDF Generator <= 2.3.0 Authenticated (Author+) Server-Side Request Forgery PoC, Patch Analysis & Rule

Medium CVE-2025-14793 in Dk Pdf (CVSS 5.0): DK PDF – WordPress PDF Generator. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.3.1.
March 23, 2026

CVE-2026-0942: Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.5 Missing Authorization to Unauthenticated Rede Order Logs Deletion PoC, Patch Analysis & Rule

Medium CVE-2026-0942 in Woo Rede (CVSS 5.3): Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.1.6.
March 23, 2026

CVE-2026-0916: Related Posts by Taxonomy <= 2.7.6 Authenticated (Contributor+) Stored Cross-Site Scripting via 'related_posts_by_tax' Shortcode PoC, Patch Analysis & Rule

Medium CVE-2026-0916 in Related Posts By Taxonomy (CVSS 6.4): Related Posts by Taxonomy. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.7.7.
March 23, 2026

CVE-2025-12957: All-in-One Video Gallery <= 4.5.7 Authenticated (Author+) Arbitrary File Upload via VTT Upload Bypass PoC, Patch Analysis & Rule

High CVE-2025-12957 in All In One Video Gallery (CVSS 8.8): All-in-One Video Gallery. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.6.4.
March 23, 2026

CVE-2025-14982: Booking Calendar <= 10.14.11 Missing Authorization to Sensitive Information Exposure PoC, Patch Analysis & Rule

Medium CVE-2025-14982 in Booking (CVSS 4.3): Booking Calendar. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 10.14.12.
March 23, 2026

CVE-2025-14384: All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure PoC, Patch Analysis & Rule

Medium CVE-2025-14384 in All In One Seo Pack (CVSS 4.3): All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update...
March 23, 2026

CVE-2025-68003: Shown Connector <= 1.2.10 Missing Authorization to Unauthenticated Settings Update PoC, Patch Analysis & Rule

Medium CVE-2025-68003 in Shown Connector (CVSS 5.3): Shown Connector. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026

CVE-2025-15370: Shield Security <= 21.0.9 Authenticated (Subscriber+) Insecure Direct Object Reference to Disable Google Authenticator PoC, Patch Analysis & Rule

Medium CVE-2025-15370 in Wp Simple Firewall (CVSS 4.3): Shield Security. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 21.0.10.
March 23, 2026

CVE-2025-13062: Supreme Modules Lite <= 2.5.62 Authenticated (Author+) Arbitrary File Upload via JSON Upload Bypass PoC, Patch Analysis & Rule

High CVE-2025-13062 in Supreme Modules For Divi (CVSS 8.8): Supreme Modules Lite. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.5.63.
March 23, 2026

CVE-2026-24599: NextMove Lite <= 2.23.0 Unauthenticated Insecure Direct Object Reference PoC, Patch Analysis & Rule

Medium CVE-2026-24599 in Woo Thank You Page Nextmove Lite (CVSS 5.3): NextMove Lite. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.24.0.
March 23, 2026

CVE-2025-12641: Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.6 Missing Authorization to Unauthenticated Role Demotion PoC, Patch Analysis & Rule

Medium CVE-2025-12641 in Awesome Support (CVSS 6.5): Awesome Support – WordPress HelpDesk & Support Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 6.3.7.
March 23, 2026

CVE-2026-0913: User Submitted Posts <= 20260110 Authenticated (Contributor+) Stored Cross-Site Scripting via 'usp_access' Shortcode PoC, Patch Analysis & Rule

Medium CVE-2026-0913 in User Submitted Posts (CVSS 6.4): User Submitted Posts. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 20260113.
March 23, 2026

CVE-2025-13859: AffiliateX 1.0.0 1.3.9.3 Authenticated (Subscriber+) Missing Authorization to Stored Cross-Site Scripting via save_customization_settings PoC, Patch Analysis & Rule

Medium CVE-2025-13859 in Affiliatex (CVSS 6.4): AffiliateX 1.0.0 - 1.3.9.3 - Authenticated (Subscriber+) Missing Authorization to Stored Cross-Site.... Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule...
March 23, 2026

CVE-2025-68015: Event Tickets with Ticket Scanner <= 2.8.5 Unauthenticated Remote Code Execution PoC, Patch Analysis & Rule

Critical CVE-2025-68015 in Event Tickets With Ticket Scanner (CVSS 9.8): Event Tickets with Ticket Scanner. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.8.6.
March 23, 2026

CVE-2026-22335: WooCommerce Frontend Manager – Ultimate < 6.7.7 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule

Medium CVE-2026-22335 in Wc Frontend Manager Ultimate (CVSS 6.5): WooCommerce Frontend Manager – Ultimate < 6.7.7 - Authenticated (Subscriber+) SQL Injection. Atomic Edge summarizes impact, exploitability, and patch details, with WAF...
March 23, 2026

CVE-2026-1003: GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools <= 4.3.0 Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion PoC, Patch Analysis & Rule

Medium CVE-2026-1003 in Getgenie (CVSS 4.3): GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.3.1.
March 23, 2026

CVE-2025-68034: CleverReach® WP <= 1.5.21 Unauthenticated SQL Injection PoC, Patch Analysis & Rule

High CVE-2025-68034 in Cleverreach Wp (CVSS 7.5): CleverReach® WP. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.5.22.
March 23, 2026

CVE-2026-24595: Zoho CRM Lead Magnet <= 1.8.1.7 Missing Authorization PoC, Patch Analysis & Rule

Medium CVE-2026-24595 in Zoho Crm Forms (CVSS 4.3): Zoho CRM Lead Magnet. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026

CVE-2026-24596: Related Posts Thumbnails Plugin for WordPress <= 4.3.2 Cross-Site Request Forgery PoC, Patch Analysis & Rule

Medium CVE-2026-24596 in Related Posts Thumbnails (CVSS 4.3): Related Posts Thumbnails Plugin for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.3.3.
Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.

See How It Works