
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
July 3, 2026
CVE-2026-13443: Tutor LMS <= 3.9.13 Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title PoC, Patch Analysis & Rule
Medium CVE-2026-13443 in Tutor (CVSS 6.4): Tutor LMS. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.9.14.
July 2, 2026
CVE-2026-11398: LatePoint <= 5.6.1 Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step PoC, Patch Analysis & Rule
Medium CVE-2026-11398 in Latepoint (CVSS 5.3): LatePoint. Atomic Edge summarizes impact, exploitability, and patch details. Update to 5.6.2.
July 2, 2026
CVE-2026-5137: RTMKit <= 2.0.7 Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-5137 in Rometheme For Elementor (CVSS 4.3): RTMKit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.0.8.
July 2, 2026
CVE-2026-11900: Ad Inserter <= 2.8.16 Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-11900 in Ad Inserter (CVSS 4.3): Ad Inserter. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.8.17.
July 2, 2026
CVE-2026-9230: Quiz and Survey Master (QSM) <= 11.1.4 Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure PoC, Patch Analysis & Rule
Medium CVE-2026-9230 in Quiz Master Next (CVSS 4.3): Quiz and Survey Master (QSM). Atomic Edge summarizes impact, exploitability, and patch details. Update to 11.1.5.
July 2, 2026
CVE-2026-8351: RTMKit <= 2.0.7 Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-8351 in Rometheme For Elementor (CVSS 6.4): RTMKit. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.0.8.
July 2, 2026
CVE-2026-8892: CM Business Directory <= 1.5.7 Authenticated (Contributor+) Stored Cross-Site Scripting via Business Address Meta Fields PoC, Patch Analysis & Rule
Medium CVE-2026-8892 in Cm Business Directory (CVSS 6.4): CM Business Directory. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.5.8.
July 2, 2026
CVE-2026-9148: Comments <= 7.6.56 Unauthenticated Stored Cross-Site Scripting via 'Website' Field PoC, Patch Analysis & Rule
High CVE-2026-9148 in Wpdiscuz (CVSS 7.2): Comments. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 7.6.57.
July 2, 2026
CVE-2026-12557: Ninja Forms File Uploads <= 3.3.29 Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST Endpoints PoC, Patch Analysis & Rule
Medium CVE-2026-12557 in Ninja Forms Uploads (CVSS 5.3): Ninja Forms - File Uploads. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
July 2, 2026
CVE-2026-11397: WP Import Export Lite <= 3.9.30 Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-11397 in Wp Import Export Lite (CVSS 5.5): WP Import Export Lite. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.9.31.
July 2, 2026
CVE-2026-14352: AR for WooCommerce <= 8.40 Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameter PoC, Patch Analysis & Rule
High CVE-2026-14352 in Ar For Woocommerce (CVSS 7.5): AR for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details. Update to 8.41.
July 2, 2026
CVE-2026-8489: Ultimate Member <= 2.11.4 Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field PoC, Patch Analysis & Rule
Medium CVE-2026-8489 in Ultimate Member (CVSS 6.4): Ultimate Member. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.12.0.
July 2, 2026
CVE-2026-9725: Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 Unauthenticated Arbitrary File Deletion PoC, Patch Analysis & Rule
Critical CVE-2026-9725 in Printcart Integration (CVSS 9.1): Printcart Web to Print Product Designer for WooCommerce. Atomic Edge summarizes impact, exploitability, and patch details. Update to 2.5.3.
July 2, 2026
CVE-2026-9626: JSON API User <= 4.1.0 Authenticated (Subscriber+) Stored Cross-Site Scripting via 'content' Parameter PoC, Patch Analysis & Rule
CVE-2026-9626 affects the Json Api User plugin for WordPress (up to version 4.1.0) with a medium severity (CVSS 6.4) cross-site scripting vulnerability. Update to version 4.1.2 to mitigate risks from authenticated attackers.
July 2, 2026
CVE-2026-13040: NEX-Forms <= 9.2.2 Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter PoC, Patch Analysis & Rule
High CVE-2026-13040 in Nex Forms Express Wp Form Builder (CVSS 7.2): NEX-Forms. Atomic Edge summarizes impact, exploitability, and patch details. Update to 9.2.3.
July 2, 2026
CVE-2026-12154: Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_id' Shortcode Attribute PoC, Patch Analysis & Rule
CVE-2026-12154 affects the Fb Reviews Widget plugin (up to version 2.7.3) with a medium severity CVSS score of 6.4. Authenticated attackers can exploit this XSS vulnerability, so upgrade to version 2.8 to mitigate risks.
July 2, 2026
CVE-2026-12920: Cookie Banner for GDPR / CCPA <= 4.3.5 Authenticated (Administrator+) SQL Injection via 's' Parameter PoC, Patch Analysis & Rule
CVE-2026-12920 affects the Gdpr Cookie Consent plugin (up to version 4.3.5) with a medium severity SQL injection vulnerability. Update to version 4.3.6 to mitigate risks of sensitive data exposure.
July 2, 2026
CVE-2026-14327: AR for WordPress <= 8.40 Unauthenticated Arbitrary File Read via 'file' Parameter PoC, Patch Analysis & Rule
CVE-2026-14327 affects the AR for WordPress plugin (up to v8.40) with a CVSS score of 7.5. Unauthenticated attackers can exploit a file upload vulnerability to read sensitive files. Update to v8.41 to mitigate this risk.
July 2, 2026
CVE-2026-12734: weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block Attribute PoC, Patch Analysis & Rule
CVE-2026-12734 affects the weDocs plugin for WordPress (up to 2.3.0) with a medium severity (CVSS 6.4) stored XSS vulnerability. Users should upgrade to version 2.3.1 to mitigate the risk of script injection by authenticated attackers.
July 2, 2026
CVE-2026-12729: weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX Action PoC, Patch Analysis & Rule
CVE-2026-12729 affects the weDocs plugin for WordPress (up to v2.3.0) with a medium severity (CVSS 4.3) vulnerability. Authenticated users can exploit it to perform unauthorized data migrations. Update to v2.3.1 to mitigate.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
