
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2025-49045: Super Interactive Maps <= 2.3 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-49045 in Super Interactive Maps (CVSS 6.1): Super Interactive Maps. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-27004: Famous Responsive Image And Video Grid Gallery WordPress <= 1.4 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-27004 in Famous_grid_image_and_video_gallery (CVSS 6.1): Famous - Responsive Image And Video Grid Gallery WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-22713: WooCommerce Orders & Customers Exporter <= 5.4 Authenticated (Subscriber+) SQL Injection PoC, Patch Analysis & Rule
Medium CVE-2025-22713 in Woocommerce Orders Ei (CVSS 6.5): WooCommerce Orders & Customers Exporter. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-14975: Custom Login Page Customizer <= 2.5.3 Unauthenticated Privilege Escalation via Password Reset PoC, Patch Analysis & Rule
Critical CVE-2025-14975 in Login Customizer (CVSS 9.8): Custom Login Page Customizer. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.5.4.
March 18, 2026
CVE-2026-0674: Campaign Monitor for WordPress <= 2.9.0 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-0674 in Forms For Campaign Monitor (CVSS 4.3): Campaign Monitor for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-14360: Blockons <= 1.2.15 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-14360 in Blockons (CVSS 5.3): Blockons. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-48094: Magic Slider <= 2.2 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-48094 in Magic_slider (CVSS 6.1): Magic Slider. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-69169: Easy Media Download <= 1.1.11 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-69169 in Easy Media Download (CVSS 6.4): Easy Media Download. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-0675: NextGEN Download Gallery <= 1.6.2 Unauthenticated Information Exposure PoC, Patch Analysis & Rule
Medium CVE-2026-0675 in Nextgen Download Gallery (CVSS 5.3): NextGEN Download Gallery. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-27002: CountDown With Image or Video Background <= 1.5 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-27002 in Countdown With Background (CVSS 6.1): CountDown With Image or Video Background. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-23993: Felan Framework <= 1.1.3 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
High CVE-2025-23993 in Felan Framework (CVSS 7.5): Felan Framework. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-49043: Magic Responsive Slider and Carousel WordPress <= 1.6 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-49043 in Magic_carousel (CVSS 6.1): Magic Responsive Slider and Carousel WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-47666: Image&Video FullScreen Background <= 1.6.7 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-47666 in Lbg_fullscreen_fullwidth_slider (CVSS 6.1): Image&Video FullScreen Background. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-27005: HTML5 Video Player <= 5.3.5 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-27005 in Lbg Vp2 Html5 Bottom (CVSS 6.1): HTML5 Video Player. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-32123: HTML5 Video Player with Playlist & Multiple Skins <= 5.3.5 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-32123 in Lbg Vp2 Html5 Rightside (CVSS 6.1): HTML5 Video Player with Playlist & Multiple Skins. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-13679: Tutor LMS <= 3.9.3 Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_details PoC, Patch Analysis & Rule
Medium CVE-2025-13679 in Tutor (CVSS 6.5): Tutor LMS. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.9.4.
March 18, 2026
CVE-2026-27094: Page Builder Gutenberg Blocks – CoBlocks <= 3.1.16 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-27094 in Coblocks (CVSS 6.4): Page Builder Gutenberg Blocks – CoBlocks. Atomic Edge summarizes impact, exploitability, and patch details. Update to 3.1.17.
March 18, 2026
CVE-2025-12640: Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.1.5 Missing Authorization to Authenticated (Author+) Media Replacement PoC, Patch Analysis & Rule
Medium CVE-2025-12640 in Folders (CVSS 4.3): Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to...
March 18, 2026
CVE-2025-14275: Jeg Elementor Kit <= 3.0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget PoC, Patch Analysis & Rule
Medium CVE-2025-14275 in Jeg Elementor Kit (CVSS 6.4): Jeg Elementor Kit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.0.2.
March 18, 2026
CVE-2025-14984: Gutenverse Form <= 2.3.2 Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload PoC, Patch Analysis & Rule
Medium CVE-2025-14984 in Gutenverse Form (CVSS 6.4): Gutenverse Form. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.4.0.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
