
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2025-69095: Reservation <= 1.7 Missing Authorization to Unauthenticated Settings Update PoC, Patch Analysis & Rule
Medium CVE-2025-69095 in Dt Reservation Plugin (CVSS 5.3): Reservation. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-22332: Tutor LMS Pro <= 3.8.3 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
High CVE-2026-22332 in Tutor Pro (CVSS 7.5): Tutor LMS Pro. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-24360: Seriously Simple Podcasting <= 3.14.1 Authenticated (Editor+) Server-Side Request Forgery PoC, Patch Analysis & Rule
Medium CVE-2026-24360 in Seriously Simple Podcasting (CVSS 5.5): Seriously Simple Podcasting. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.14.2.
March 18, 2026
CVE-2026-24608: Laurent Core <= 2.4.1 Authenticated (Contributor+) Local File Inclusion PoC, Patch Analysis & Rule
High CVE-2026-24608 in Laurent Core (CVSS 7.5): Laurent Core. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-68912: HDForms <= 1.6.1 Unauthenticated Arbitrary File Deletion PoC, Patch Analysis & Rule
Critical CVE-2025-68912 in Hdforms (CVSS 9.1): HDForms. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-27050: RealPress – Real Estate Plugin <= 1.1.0 Cross-Site Request Forgery PoC, Patch Analysis & Rule
Medium CVE-2026-27050 in Realpress (CVSS 4.3): RealPress – Real Estate Plugin. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.1.1.
March 18, 2026
CVE-2025-68906: JNews Video <= 11.0.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-68906 in Jnews Video (CVSS 6.1): JNews - Video. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-24614: Flex QR Code Generator <= 1.2.10 Authenticated (Author+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-24614 in Flex Qr Code Generator (CVSS 6.4): Flex QR Code Generator. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-24613: Ecwid Shopping Cart <= 7.0.6 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-24613 in Ecwid Shopping Cart (CVSS 5.3): Ecwid Shopping Cart. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 7.0.7.
March 18, 2026
CVE-2025-14507: EventPrime Events Calendar, Bookings and Tickets <= 4.2.7.0 Unauthenticated Sensitive Information Exposure via REST API PoC, Patch Analysis & Rule
Medium CVE-2025-14507 in Eventprime Event Calendar Management (CVSS 5.3): EventPrime - Events Calendar, Bookings and Tickets. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.2.8.0.
March 18, 2026
CVE-2025-68905: JNews Pay Writer <= 11.0.0 Authenticated (Subscriber+) Local File Inclusion PoC, Patch Analysis & Rule
High CVE-2025-68905 in Jnews Pay Writer (CVSS 7.5): JNews - Pay Writer. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-49049: DZS Video Gallery <= 12.39 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2025-49049 in Dzs Videogallery (CVSS 6.5): DZS Video Gallery. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-15030: User Profile Builder <= 3.15.1 Unauthenticated Privilege Escalation via Account Takeover PoC, Patch Analysis & Rule
Critical CVE-2025-15030 in Profile Builder (CVSS 9.8): User Profile Builder. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.15.2.
March 18, 2026
CVE-2026-0684: CP Image Store with Slideshow <= 1.1.9 Missing Authorization to Authenticated (Contributor+) Arbitrary Product Import PoC, Patch Analysis & Rule
Medium CVE-2026-0684 in Cp Image Store (CVSS 4.3): CP Image Store with Slideshow. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.2.0.
March 18, 2026
CVE-2025-14001: WP Duplicate Page <= 1.8 Missing Authorization to Authenticated (Contributor+) Arbitrary Post Duplication PoC, Patch Analysis & Rule
Medium CVE-2025-14001 in Wp Duplicate Page (CVSS 5.4): WP Duplicate Page. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.8.1.
March 18, 2026
CVE-2025-49050: Lead Capturing Pages <= 2.5 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2025-49050 in Wp Lead Capture (CVSS 6.5): Lead Capturing Pages. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-50004: JupiterX Core <= 4.10.1 Authenticated (Contributor+) PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2025-50004 in Jupiterx Core (CVSS 7.5): JupiterX Core. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.11.0.
March 18, 2026
CVE-2025-69362: UiChemy <= 4.4.2 Authenticated (Author+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-69362 in Uichemy (CVSS 6.4): UiChemy. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.4.3.
March 18, 2026
CVE-2025-69363: Responsive Addons for Elementor <= 2.0.8 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-69363 in Responsive Addons For Elementor (CVSS 4.3): Responsive Addons for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.0.9.
March 18, 2026
CVE-2025-49066: Accordion Slider PRO <= 1.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-49066 in Accordion_slider_pro (CVSS 6.1): Accordion Slider PRO. Atomic Edge summarizes impact, exploitability, and patch details.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
