Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
high
CVE-2026-6897: Wishlist Member <= 3.30.1 Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Update via 'wishlistmember_team_accounts_save_settings' AJAX action PoC, Patch Analysis & Rule
May 22, 2026
High CVE-2026-6897 in Wishlist Member X (CVSS 8.8): Wishlist Member. Atomic Edge summarizes impact, exploitability, and patch details, with WAF…
CVE-2026-8073: Kirki <= 6.0.6 Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIP PoC, Patch Analysis & Rule
May 22, 2026
High CVE-2026-8073 in Kirki (CVSS 7.5): Kirki. Atomic Edge summarizes impact, exploitability, and patch details. Update to 6.0.7.
CVE-2026-42672: WP Directory Kit <= 1.5.1 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
May 22, 2026
High CVE-2026-42672 in Wpdirectorykit (CVSS 7.5): WP Directory Kit. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule…
CVE-2026-42678: GiveWP – Donation Plugin and Fundraising Platform <= 4.14.5 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
May 22, 2026
High CVE-2026-42678 in Give (CVSS 7.2): GiveWP – Donation Plugin and Fundraising Platform. Atomic Edge summarizes impact, exploitability, and patch…
CVE-2026-8679: AudioIgniter Music Player <= 2.0.2 Unauthenticated Insecure Direct Object Reference to 'audioigniter_playlist_id' Parameter PoC, Patch Analysis & Rule
May 21, 2026
High CVE-2026-8679 in Audioigniter (CVSS 7.5): AudioIgniter Music Player. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule…
CVE-2026-9011: Ditty <= 3.1.65 Missing Authorization to Unauthenticated Sensitive Information Disclosure via ditty_init AJAX Action PoC, Patch Analysis & Rule
May 21, 2026
High CVE-2026-9011 in Ditty News Ticker (CVSS 7.5): Ditty. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule…
CVE-2026-9018: Easy Elements for Elementor – Addons & Website Templates <= 1.4.5 Unauthenticated Privilege Escalation via 'custom_meta' Parameter PoC, Patch Analysis & Rule
May 21, 2026
High CVE-2026-9018 in Easy Elements (CVSS 8.8): Easy Elements for Elementor – Addons & Website Templates. Atomic Edge summarizes impact,…
CVE-2026-4834: WP ERP Pro <= 1.5.1 Unauthenticated SQL Injection via 'search_key' Parameter PoC, Patch Analysis & Rule
May 21, 2026
High CVE-2026-4834 in Erp Pro (CVSS 7.5): WP ERP Pro. Atomic Edge summarizes impact, exploitability, and patch details.
CVE-2026-6456: Account Switcher <= 1.0.2 Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation PoC, Patch Analysis & Rule
May 20, 2026
High CVE-2026-6456 in Account Switcher (CVSS 8.8): Account Switcher. Atomic Edge summarizes impact, exploitability, and patch details.
CVE-2026-7613: Cost of Goods by PixelYourSite <= 1.2.12 Unauthenticated Stored Cross-Site Scripting via Cost of Goods Import PoC, Patch Analysis & Rule
May 19, 2026
High CVE-2026-7613 in Pixel Cost Of Goods (CVSS 7.2): Cost of Goods by PixelYourSite. Atomic Edge summarizes impact, exploitability, and…
CVE-2026-5200: AcyMailing <= 10.8.2 Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via 'acymailing_router' PoC, Patch Analysis & Rule
May 19, 2026
High CVE-2026-5200 in Acymailing (CVSS 8.8): AcyMailing. Atomic Edge summarizes impact, exploitability, and patch details. Update to 10.9.0.
CVE-2026-7522: Advanced Database Cleaner – Premium <= 4.1.0 Authenticated (Subscriber+) Local File Inclusion via 'template' PoC, Patch Analysis & Rule
May 19, 2026
High CVE-2026-7522 in Advanced Database Cleaner Premium (CVSS 8.8): Advanced Database Cleaner – Premium. Atomic Edge summarizes impact, exploitability, and…
CVE-2026-7467: Read More & Accordion <= 3.5.7 Privilege Escalation via importData PoC, Patch Analysis & Rule
May 19, 2026
High CVE-2026-7467 in Expand Maker (CVSS 8.8): Read More & Accordion. Atomic Edge summarizes impact, exploitability, and patch details, with…
CVE-2026-3985: Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 Unauthenticated SQL Injection via 'checkout_uuid' Parameter PoC, Patch Analysis & Rule
May 19, 2026
High CVE-2026-3985 in Creative Mail By Constant Contact (CVSS 7.5): Creative Mail – Easier WordPress & WooCommerce Email Marketing. Atomic…
CVE-2026-9010: Boost <= 2.0.3 Unauthenticated Blind SQL Injection via Multiple Parameters PoC, Patch Analysis & Rule
May 19, 2026
High CVE-2026-9010 in Boost (CVSS 7.5): Boost. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
CVE-2026-8912: Contest Gallery <= 28.1.6 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
May 18, 2026
High CVE-2026-8912 in Contest Gallery (CVSS 7.5): Contest Gallery. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule…
CVE-2026-42639: GD Rating System <= 3.6.2 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
May 18, 2026
High CVE-2026-42639 in Gd Rating System (CVSS 7.5): GD Rating System. Atomic Edge summarizes impact, exploitability, and patch details. Update…
CVE-2026-5306: Check & Log Email – Easy Email Testing & Mail logging < 2.0.13 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
May 18, 2026
High CVE-2026-5306 in Check Email (CVSS 7.2): Check & Log Email – Easy Email Testing & Mail logging < 2.0.13…
CVE-2026-42647: JoomSport – for Sports: Team & League, Football, Hockey & more <= 5.7.7 Unauthenticated SQL Injection PoC, Patch Analysis & Rule
May 18, 2026
High CVE-2026-42647 in Joomsport Sports League Results Management (CVSS 7.5): JoomSport – for Sports: Team & League, Football, Hockey &…
CVE-2026-42385: Profile Builder Pro <= 3.15.0 Unauthenticated Stored Cross-Site Scripting PoC, Patch Analysis & Rule
May 18, 2026
High CVE-2026-42385 in Profile Builder Pro (CVSS 7.2): Profile Builder Pro. Atomic Edge summarizes impact, exploitability, and patch details, with…
←
1
…
7
8
9
10
11
…
32
→