
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
2026-04-16
CVE-2026-5427: Kubio AI Page Builder <= 2.7.2 – Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block Attributes (kubio)
The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due to insufficient capability checks in the kubio_rest_pre_insert_import_assets() function, which is hooked to the rest_pre_insert_cve_proof filter for posts, pages, templates, and template parts. When a post is created or updated via the REST API, Kubio…
2026-04-16
CVE-2026-40725: WooCommerce Product Filters < 2.0.6 – Unauthenticated PHP Object Injection (woocommerce-product-filters)
The WooCommerce Product Filters plugin for WordPress is vulnerable to PHP Object Injection in versions up to 2.0.6 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin…
2026-04-16
CVE-2026-39540: Shipment Tracker for Woocommerce <= 1.5.3.2 – Authenticated (Subscriber+) Stored Cross-Site Scripting (shipment-tracker-for-woocommerce)
The Shipment Tracker for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses…
2026-04-16
CVE-2026-40724: Client Portal (Pro) <= 5.6.2 – Authenticated (CP Client+) Arbitrary File Download (leco-client-portal)
The Client Portal Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.6.2. This makes it possible for authenticated attackers, with Custom-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
2026-04-15
CVE-2026-6370: Mini Ajax Cart for WooCommerce <= 1.3.4 – Authenticated (Author+) Stored Cross-Site Scripting (mini-ajax-woo-cart)
The Mini Ajax Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user…
2026-04-15
CVE-2026-40784: FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration <= 1.91.2 – Authenticated (Board Member+) Insecure Direct Object Reference (fluent-boards)
The FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.91.2 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Custom-level access and above, to perform…
2026-04-15
CVE-2025-63029: WCFM Marketplace – Multivendor Marketplace for WooCommerce <= 3.7.1 – Authenticated (Store vendor+) SQL Injection (wc-multivendor-marketplace)
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with store vendor-level access and above,…
2026-04-15
CVE-2026-6372: Accept Cryptocurrencies with Plisio <= 2.0.6 – Missing Authorization (plisio-payment-gateway-for-woocommerce)
The Accept Cryptocurrencies with Plisio plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
2026-04-15
CVE-2025-15636: Video Gallery – YouTube Gallery & Responsive Video Playlist <= 3.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting (youtube-showcase)
The Video Gallery – YouTube Gallery & Responsive Video Playlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will…
2026-04-15
CVE-2025-15635: Smart Online Order for Clover <= 1.6.0 – Cross-Site Request Forgery (clover-online-orders)
The Smart Online Order for Clover plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a…
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
