
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 23, 2026
CVE-2025-68896: WDV One Page Docs <= 1.2.4 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-68896 in Wdv One Page Docs (CVSS 5.3): WDV One Page Docs. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026
CVE-2025-68884: Simple Redirect <= 1.1 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-68884 in Wp Simple Redirect (CVSS 6.1): Simple Redirect. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026
CVE-2026-24594: Livemesh Addons for WPBakery Page Builder <= 3.9.4 Authenticated (Editor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-24594 in Addons For Visual Composer (CVSS 4.4): Livemesh Addons for WPBakery Page Builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026
CVE-2025-68864: Infility Global <= 2.14.49 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2025-68864 in Infility Global (CVSS 7.2): Infility Global. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026
CVE-2025-68007: Event Espresso 4 Decaf <= 5.0.37.decaf Missing Authorization to Unauthenticated Settings Change PoC, Patch Analysis & Rule
Medium CVE-2025-68007 in Event Espresso Decaf (CVSS 6.5): Event Espresso 4 Decaf. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 5.0.54.decaf.
March 23, 2026
CVE-2025-68041: Omnichannel for WooCommerce <= 1.3.65 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2025-68041 in Codistoconnect (CVSS 7.2): Omnichannel for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026
CVE-2026-24598: Multilanguage by BestWebSoft <= 1.5.2 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24598 in Multilanguage (CVSS 4.3): Multilanguage by BestWebSoft. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026
CVE-2026-24388: WPMasterToolKit <= 2.14.0 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24388 in Wpmastertoolkit (CVSS 4.3): WPMasterToolKit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.14.1.
March 23, 2026
CVE-2025-69101: Workreap Core <= 3.4.0 Authentication Bypass PoC, Patch Analysis & Rule
Critical CVE-2025-69101 in Workreap_core (CVSS 9.8): Workreap Core. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026
CVE-2025-69102: Test Email <= 1.1.7 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-69102 in Wp Test Email (CVSS 6.1): Test Email. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026
CVE-2026-22334: Woocommerce Book Price <= 1.3 Authenticated (Subscriber++) Arbitrary File Download PoC, Patch Analysis & Rule
Medium CVE-2026-22334 in Woo Book Price (CVSS 6.5): Woocommerce Book Price. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026
CVE-2025-68898: Synergy Project Manager <= 1.5 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
High CVE-2025-68898 in Synergy Project Manager (CVSS 7.2): Synergy Project Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026
CVE-2025-14457: Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 Missing Authorization to Unauthenticated File Deletion PoC, Patch Analysis & Rule
Low CVE-2025-14457 in Drag And Drop Multiple File Upload Contact Form 7 (CVSS 3.7): Drag and Drop Multiple File Upload for Contact Form 7. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update...
March 23, 2026
CVE-2026-24361: LearnPress – Course Review <= 4.1.9 Authenticated (Learnpress student+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-24361 in Learnpress Course Review (CVSS 6.4): LearnPress – Course Review. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.2.0.
March 23, 2026
CVE-2025-68001: g-FFL Checkout <= 2.1.0 Unauthenticated Arbitrary File Upload PoC, Patch Analysis & Rule
Critical CVE-2025-68001 in G Ffl Checkout (CVSS 9.8): g-FFL Checkout. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.1.1.
March 23, 2026
CVE-2025-14448: WP-Members Membership Plugin <= 3.5.4.3 Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Checkbox and Multiple Select User Profile Fields PoC, Patch Analysis & Rule
Medium CVE-2025-14448 in Wp Members (CVSS 5.4): WP-Members Membership Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.5.4.4.
March 23, 2026
CVE-2026-24602: Raptive Ads <= 3.10.0 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24602 in Adthrive Ads (CVSS 5.3): Raptive Ads. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.11.0.
March 23, 2026
CVE-2026-24603: Universal Google Adsense and Ads manager <= 1.1.8 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24603 in Universal Google Adsense And Ads Manager (CVSS 5.3): Universal Google Adsense and Ads manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 23, 2026
CVE-2025-12166: Simply Schedule Appointments <= 1.6.9.9 Unauthenticated SQL Injection via `order` and `append_where_sql` Parameters PoC, Patch Analysis & Rule
High CVE-2025-12166 in Simply Schedule Appointments (CVSS 7.5): Simply Schedule Appointments. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.6.9.13.
March 23, 2026
CVE-2026-24604: Simple GDPR Cookie Compliance <= 2.0.0 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24604 in Simple Gdpr Cookie Compliance (CVSS 5.3): Simple GDPR Cookie Compliance. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.0.1.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
