Skip to main content
Skip to footer
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Home
CVE Analysis
How it Works
Resources
Pricing
Log in
Create Account
Severity:
low
CVE-2025-12656: Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 Authenticated (Admin+) Arbitrary Directory Deletion PoC, Patch Analysis & Rule
June 12, 2026
Low CVE-2025-12656 in Wpvivid Backuprestore (CVSS 3.8): Migration, Backup, Staging – WPvivid Backup & Migration. Atomic Edge summarizes impact, exploitability,…
CVE-2026-3339: Keep Backup Daily <= 2.1.1 Authenticated (Admin+) Limited Path Traversal via 'kbd_path' Parameter PoC, Patch Analysis & Rule
March 30, 2026
CVE-2026-3339 affects the Keep Backup Daily plugin (up to v2.1.1) with a low severity (CVSS 2.7) local file inclusion vulnerability.…
CVE-2026-0682: Church Admin <= 5.0.28 Authenticated (Administrator+) Blind Server-Side Request Forgery via 'audio_url' Parameter PoC, Patch Analysis & Rule
March 23, 2026
CVE-2026-0682 affects the Church Admin plugin (up to v5.0.28) with a low severity CVSS of 2.2. Authenticated admins can exploit…
CVE-2025-14457: Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 Missing Authorization to Unauthenticated File Deletion PoC, Patch Analysis & Rule
March 23, 2026
CVE-2025-14457 affects the Drag And Drop Multiple File Upload Contact Form 7 plugin (up to v1.3.9.2), allowing unauthenticated users to…
CVE-2025-12958: Rankology SEO and Analytics Tool <= 2.0 Incorrect Authorization to Authenticated (Editor+) Header & Footer Code Creation PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-12958 affects the Rankology SEO and Analytics Tool plugin (up to version 2.0) with a low severity (CVSS 2.7). Authenticated…
CVE-2025-67954: Salon booking system <= 10.30.3 Authenticated (Subscriber+) Information Exposure PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-67954 affects the Salon Booking System plugin for WordPress, allowing authenticated users to access sensitive data. Update to version 10.30.4…
CVE-2026-0633: MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 Unauthenticated Form Submission Exposure via Forgeable Cookie Value PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-0633 affects the Metform plugin (up to v4.1.0) with a CVSS score of 3.7, allowing unauthenticated access to sensitive form…
CVE-2025-14270: OneClick Chat to Order <= 1.0.9 Missing Authorization to Authenticated (Editor+) Plugin Settings Update PoC, Patch Analysis & Rule
March 18, 2026
CVE-2025-14270 affects the OneClick Whatsapp Order plugin (v1.0.9) with a low severity CVSS of 2.7. Authenticated attackers can bypass authorization…
CVE-2026-1831: YayMail <= 4.3.2 Missing Authorization to Authenticated (Shop Manager+) Plugin Installation and Activation PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1831 affects the YayMail plugin for WordPress (up to 4.3.2) with a CVSS score of 2.7. Authenticated attackers can exploit…
CVE-2026-2419: WP-DownloadManager <= 1.69 Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'download_path' Parameter PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-2419 affects the WP DownloadManager plugin (up to v1.69) with a low severity (CVSS 2.7) path traversal vulnerability. Update to…
CVE-2026-1582: WP All Export <= 1.4.14 Unauthenticated Sensitive Information Exposure via PHP Type Juggling PoC, Patch Analysis & Rule
March 18, 2026
CVE-2026-1582 affects WP All Export plugin versions up to 1.4.14, allowing unauthenticated access to sensitive data. Upgrade to 1.4.15 to…