
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
March 18, 2026
CVE-2025-68044: Five Star Restaurant Reservations <= 2.7.4 Unauthenticated Insecure Direct Object Reference PoC, Patch Analysis & Rule
Medium CVE-2025-68044 in Restaurant Reservations (CVSS 5.3): Five Star Restaurant Reservations. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.7.5.
March 18, 2026
CVE-2026-22461: CTX Feed <= 6.6.18 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2026-22461 in Webappick Product Feed For Woocommerce (CVSS 5.3): CTX Feed. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 6.6.19.
March 18, 2026
CVE-2025-68509: User Submitted Posts <= 20251121 Unauthenticated Open Redirect PoC, Patch Analysis & Rule
Medium CVE-2025-68509 in User Submitted Posts (CVSS 5.3): User Submitted Posts. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 20251210.
March 18, 2026
CVE-2025-14627: WP Import – Ultimate CSV XML Importer for WordPress <= 7.35 Authenticated (Contributor+) Server-Side Request Forgery via Bitly Shortlink Bypass PoC, Patch Analysis & Rule
Medium CVE-2025-14627 in Wp Ultimate Csv Importer (CVSS 6.4): WP Import – Ultimate CSV XML Importer for WordPress. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 7.36.
March 18, 2026
CVE-2025-14998: Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 Unauthenticated Privilege Escalation via Account Takeover PoC, Patch Analysis & Rule
Critical CVE-2025-14998 in Branda White Labeling (CVSS 9.8): Branda – White Label & Branding, Free Login Page Customizer. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.4.29.
March 18, 2026
CVE-2025-14047: WP User Frontend <= 4.2.4 Missing Authorization to Unauthenticated Arbitrary Attachment Deletion PoC, Patch Analysis & Rule
Medium CVE-2025-14047 in Wp User Frontend (CVSS 5.3): WP User Frontend. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.2.5.
March 18, 2026
CVE-2025-69055: BM Content Builder < 3.16.3.3 Authenticated (Contributor+) Arbitrary File Download PoC, Patch Analysis & Rule
Medium CVE-2025-69055 in Bm Builder (CVSS 6.5): BM Content Builder < 3.16.3.3 - Authenticated (Contributor+) Arbitrary File Download. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2026-22388: Owl Carousel WP <= 2.2.2 Authenticated (Editor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2026-22388 in Owl Carousel Wp (CVSS 4.4): Owl Carousel WP. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-62743: MyBookTable Bookstore <= 3.5.6 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-62743 in Mybooktable (CVSS 6.4): MyBookTable Bookstore. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-62113: Co-marquage service-public.fr <= 0.5.77 Cross-Site Request Forgery PoC, Patch Analysis & Rule
Medium CVE-2025-62113 in Co Marquage Service Public (CVSS 4.3): Co-marquage service-public.fr. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-68867: Effect Maker <= 1.2.1 Authenticated (Subscriber+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-68867 in Effect Maker (CVSS 6.4): Effect Maker. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-69341: WeDesignTech Ultimate Booking Addon <= 1.0.3 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-69341 in Wedesigntech Ultimate Booking Addon (CVSS 4.3): WeDesignTech Ultimate Booking Addon. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-68529: Email Capture <= 3.12.5 Cross-Site Request Forgery PoC, Patch Analysis & Rule
Medium CVE-2025-68529 in Wp Email Capture (CVSS 4.3): Email Capture. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.12.6.
March 18, 2026
CVE-2025-67911: Newsletters <= 4.11 Unauthenticated PHP Object Injection PoC, Patch Analysis & Rule
High CVE-2025-67911 in Newsletters Lite (CVSS 8.1): Newsletters. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-66153: Headinger for Elementor <= 1.1.4 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-66153 in Headinger Elementor (CVSS 4.3): Headinger for Elementor. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-62989: Cooked <= 1.11.3 Authenticated (Administrator+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-62989 in Cooked (CVSS 4.4): Cooked. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.11.4.
March 18, 2026
CVE-2025-69084: Photo Gallery <= 2.7.7.26 Reflected Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-69084 in Gt3 Photo Video Gallery (CVSS 6.1): Photo Gallery. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 2.7.7.27.
March 18, 2026
CVE-2025-66150: Appender <= 1.1.1 Missing Authorization PoC, Patch Analysis & Rule
Medium CVE-2025-66150 in Appender (CVSS 4.3): Appender. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-62121: Logo Slider , Logo Carousel , Logo showcase , Client Logo <= 1.8.1 Authenticated (Editor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-62121 in Tc Logo Slider (CVSS 4.4): Logo Slider , Logo Carousel , Logo showcase , Client Logo. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
March 18, 2026
CVE-2025-62125: Custom Background Changer <= 3.0 Authenticated (Contributor+) Stored Cross-Site Scripting PoC, Patch Analysis & Rule
Medium CVE-2025-62125 in Custom Background Changer (CVSS 6.4): Custom Background Changer. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
