Atomicorp WAF Research Notes
Research Update - 2026-07-21
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2017-18580 | WordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Execution | 377360 |
| CVE-2021-24215 | Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalation | 377360 |
| CVE-2021-34621 | WordPress ProfilePress 3.0.0-3.1.3 - Admin User Creation Weakness | 377360 |
| CVE-2021-4449 | ZoomSounds Plugin - Unauthenticated Arbitrary File Upload | 392301 |
| CVE-2023-33831 | FUXA - Unauthenticated Remote Code Execution | 340095 , 344370 , 345240 , 380026 |
| CVE-2024-3605 | WP Hotel Booking <= 2.1.0 - SQL Injection | 341245 , 380026 , 380122 |
| CVE-2024-37843 | Craft CMS <=v3.7.31 - SQL Injection | 344378 |
| CVE-2025-11833 | Post SMTP <= 3.6.0 - Email Log Disclosure | 377360 |
| CVE-2025-1562 | Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Control | 377360 |
| CVE-2025-54782 | NestJS DevTools Integration - Remote Code Execution | 345240 |
| CVE-2026-41940 | cPanel & WHM - Authentication Bypass via Session-File CRLF Injection | 377364 |
| CVE-2024-8673 | Z-Downloads < 1.11.7 - Cross-Site Scripting | 377360 |
| CVE-2025-49029 | WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code Execution | 377360 |
| CVE-2025-1302 | JSONPath Plus < 10.3.0 - Remote Code Execution | 345240 , 346755 , 360151 , 380026 |
| CVE-2020-9043 | WordPress wpCentral <1.5.1 - Information Disclosure | 377360 |
| CVE-2021-24347 | WordPress SP Project & Document Manager <4.22 - Authenticated Shell Upload | 377360 |
| CVE-2021-25082 | WordPress Popup Builder < 4.0.7 - Remote Code Execution | 340162 , 340165 , 377360 , 390904 , 398007 |
| CVE-2022-0439 | Email Subscribers & Newsletters <= 5.3.1 - Authenticated SQL Injection | 340016 , 377360 , 380122 |
| CVE-2022-1329 | Elementor Website Builder - Remote Code Execution | 377360 |
| CVE-2023-23897 | Ozette Plugins - Cross-Site Request Forgery | 345490 , 377360 |
| CVE-2023-48777 | WordPress Elementor 3.18.1 - File Upload/Remote Code Execution | 377360 |
| CVE-2025-2075 | Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation | 377360 |
| CVE-2012-10018 | WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Authenticated Stored XSS via SVG File Upload | 346755 , 377360 |
| CVE-2018-1335 | Apache Tika < 1.1.8 - Header Command Injection | 340138 , 391213 |
| CVE-2020-36836 | WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletion | 340748 , 347006 , 377360 |
| CVE-2021-24170 | User Profile Picture < 2.5.0 - Sensitive Information Disclosure | 377360 |
| CVE-2021-24644 | Images to WebP < 1.9 - Authenticated Local File Inclusion | 340007 , 377360 |
| CVE-2024-45293 | TablePress < 2.4.3 - XXE Injection | 377360 |
| CVE-2026-9282 | W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read | 336461 , 344360 |
| CVE-2021-24155 | WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload | 377360 |
| CVE-2021-24970 | WordPress All-In-One Video Gallery <2.5.0 - Local File Inclusion | 377360 |
| CVE-2023-0900 | AP Pricing Tables Lite <= 1.1.6 - SQL Injection | 377360 |
| CVE-2023-47873 | WordPress WP Child Theme Generator < 1.1.3 - Arbitrary File Upload | 377360 |
| CVE-2025-5961 | WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload | 377360 |
| CVE-2024-10152 | Simple Certain Time to Show Content - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-12638 | Bulk Me Now! Plugin <= 2.0 - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-12749 | WordPress Competition Form Plugin <= 2.0 - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-12878 | Lazy Blocks <= 3.8.2 - Cross-Site Scripting | 340148 , 341266 , 346755 , 377360 |
| CVE-2024-13055 | Dyn Business Panel Plugin <= 1.0.0 - Cross-Site Scripting | 341266 , 377360 |
| CVE-2024-13094 | WP Triggers Lite - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-13330 | JustRows WordPress - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-13569 | WordPress Front End Users - Reflected XSS | 341266 , 377360 |
| CVE-2015-2755 | WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scripting | 346755 , 377360 |
| CVE-2020-8615 | Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery | 345490 , 377360 |
| CVE-2022-1398 | External Media without Import <=1.1.2 - Authenticated Blind Server-Side Request Forgery | 377360 |
| CVE-2023-3345 | LMS by Masteriyo < 1.6.8 - Information Exposure | 377360 |
| CVE-2024-9765 | EKC Tournament Manager WordPress plugin - Path Traversal | 344360 , 347009 , 377360 |
| CVE-2025-13652 | WordPress CBX Bookmark & Favorite Plugin <= 2.0.4 - SQL Injection | 340016 , 377360 , 380122 |
| CVE-2025-13418 | Responsive Pricing Table <= 5.1.12 - Cross-Site Scripting | 346755 , 377360 |
| CVE-2015-8350 | WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS | 340148 , 341266 , 346755 , 377360 |
| CVE-2020-36731 | Flexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Update | 346755 , 377360 , 390585 |
| CVE-2021-24165 | WordPress Ninja Forms <3.4.34 - Open Redirect | 377360 |
| CVE-2021-24213 | GiveWP <= 2.9.7 - Cross-Site Scripting | 340148 , 341266 , 346755 , 377360 |
| CVE-2021-24286 | WordPress Plugin Redirect 404 to Parent 1.3.0 - Cross-Site Scripting | 346755 , 377360 |
| CVE-2021-24287 | WordPress Select All Categories and Taxonomies <1.3.2 - Cross-Site Scripting | 346755 , 377360 |
| CVE-2021-24452 | WordPress W3 Total Cache <2.1.5 - Cross-Site Scripting | 346755 , 377360 |
| CVE-2021-24657 | Limit Login Attempts WordPress - Stored Cross-site Scripting | 377360 |
| CVE-2021-24876 | Registrations for The Events Calendar < 2.7.5 - Authenticated Reflected Cross-Site Scripting | 346755 , 347198 , 377360 |
| CVE-2022-0189 | WordPress RSS Aggregator < 4.20 - Authenticated Cross-Site Scripting | 346755 , 377360 |
| CVE-2023-0514 | Membership Database <= 1.0 - Cross-Site Scripting | 346755 , 377360 |
| CVE-2023-2272 | Tiempo.com <= 0.1.2 - Cross-Site Scripting | 377360 |
| CVE-2023-37979 | Ninja Forms < 3.6.26 - Cross-Site Scripting | 346755 , 377360 |
| CVE-2024-12732 | AffiliateImporterEb <= 1.0.6 - Reflected XSS | 341266 , 346755 , 377360 |
| CVE-2024-12734 | Advance Post Prefix WordPress plugin - Reflected XSS | 341266 , 377360 |
| CVE-2024-12737 | WP BASE Booking - Reflected XSS | 341266 , 346755 , 377360 |
| CVE-2024-12873 | Custom Field Manager WordPress - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-13112 | WP MediaTagger <= 4.1.1 - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-13114 | WP Projects Portfolio <= 3.0 - Cross-Site Scripting | 340148 , 341266 , 346755 , 377360 |
| CVE-2024-13219 | Privacy Policy Genius - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-13220 | WordPress Google Map Professional - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-13221 | Fantastic ElasticSearch Plugin <= 4.1.0 - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-13224 | SlideDeck 1 Lite Content Slider - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-13225 | ECT Home Page Products - Reflected XSS | 341266 , 346755 , 377360 |
| CVE-2024-13226 | A5 Custom Login Page - Reflected XSS | 341266 , 346755 , 377360 |
| CVE-2024-13325 | Glossy WordPress - Reflected XSS | 341266 , 377360 |
| CVE-2024-13326 | iBuildApp <= 0.2.0 - Reflected Cross-Site Scripting | 341266 , 377360 |
| CVE-2024-13327 | Musicbox WordPress - Reflected XSS | 341266 , 346755 , 377360 |
| CVE-2024-13331 | WP Dream Carousel < 1.0.1b - Cross-Site Scripting | 340148 , 341266 , 346755 , 377360 |
| CVE-2024-13492 | Guten Free Options - Cross Site Scripting | 341266 , 377360 |
| CVE-2024-13543 | Zarinpal Paid Download - Reflected XSS | 341266 , 346755 , 377360 |
| CVE-2024-13570 | WordPress Stray Random Quotes <= 1.9.9 - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-13619 | LifterLMS < 8.0.1 - Cross-Site Scripting | 340148 , 341266 , 346755 , 377360 |
| CVE-2024-13628 | WP Pricing Table - Reflected XSS | 341266 , 346755 , 377360 |
| CVE-2024-13630 | NewsTicker <= 1.0 - Reflected Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-13634 | Post Sync Plugin <= 1.1 - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-29138 | WordPress Restrict User Access <= 2.5 - Cross-Site Scripting | 346755 , 377360 |
| CVE-2024-29792 | Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scripting | 346755 , 347198 , 377360 |
| CVE-2024-30194 | Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scripting | 333141 , 340149 , 344361 , 344364 , 346755 , 347198 , 377360 |
| CVE-2024-37261 | WP-Lister Lite for Amazon <= 2.6.16 - Cross-Site Scripting | 346755 , 377360 |
| CVE-2024-39646 | WordPress Custom 404 Pro <= 3.11.1 - Reflected XSS | 346755 , 347198 , 377360 |
| CVE-2024-43971 | Sunshine Photo Cart <= 3.2.5 - Reflected Cross-Site Scripting | 344361 , 344364 , 347198 , 377360 |
| CVE-2024-4439 | WordPress Core <6.5.2 - Cross-Site Scripting | 377360 |
| CVE-2024-4455 | YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site Scripting | 377360 |
| CVE-2024-6753 | Social Auto Poster <= 5.3.14 - Stored Cross-Site Scripting | 377360 |
| CVE-2025-4652 | Broadstreet WordPress plugin - Reflected XSS | 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 377360 |
| CVE-2026-1296 | Frontend Post Submission Manager Lite <= 1.2.7 - Open Redirect | 377360 |
| CVE-2017-8295 | WordPress Core < 4.7.4 - Unauthorized Password Reset | 377360 |
| CVE-2017-14725 | WordPress < 4.8.2 - Authenticated Open Redirect | 377360 |
| CVE-2017-17092 | WordPress < 4.9.1 - Authenticated JavaScript File Upload | 377360 |
| CVE-2018-16363 | WordPress File Manager < 3.0 - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2021-33851 | WordPress Customize Login Image <3.5.3 - Cross-Site Scripting | 377360 |
| CVE-2021-36873 | WordPress iQ Block Country <=1.2.11 - Cross-Site Scripting | 377360 |
| CVE-2022-0765 | WordPress Loco Translate < 2.6.1 - Cross-Site Scripting | 377360 |
| CVE-2022-3506 | WordPress Related Posts <2.1.3 - Stored Cross-Site Scripting | 377360 |
| CVE-2023-7246 | System Dashboard < 2.8.10 - Cross-Site Scripting | 377360 |
| CVE-2024-10146 | Simple File List < 6.1.13 - Reflected Cross-Site Scripting | 340087 , 341266 , 346755 , 377360 |
| CVE-2024-13097 | WP Finance Plugin <= 1.3.6 - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-13098 | WordPress Email Newsletter - Reflected XSS | 341266 , 346755 , 377360 |
| CVE-2024-13099 | Widget4Call WordPress - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2024-2473 | WPS Hide Login <= 1.9.15.2 - Login Page Disclosure | 377360 |
| CVE-2022-2863 | WordPress WPvivid Backup <0.9.76 - Local File Inclusion | 377360 |
| CVE-2024-10708 | System Dashboard < 2.8.15 - Admin+ Path Traversal | 336461 , 344360 , 377360 , 381206 |
| CVE-2021-24681 | Duplicate Page WordPress - Stored Cross-Site Scripting | 377360 |
| CVE-2022-0535 | WordPress E2Pdf <1.16.45 - Cross-Site Scripting | 377360 |
| CVE-2022-0873 | WordPress Gmedia Photo Gallery Plugin < 1.20.0 - Cross-Site Scripting | 377360 |
| CVE-2022-1029 | Limit Login Attempts - Stored Cross-Site Scripting | 377360 |
| CVE-2022-4260 | WordPress WP-Ban <1.69.1 - Stored Cross-Site Scripting | 377360 |
| CVE-2023-2009 | Pretty Url <= 1.5.4 - Cross-Site Scripting | 377360 |
| CVE-2023-2178 | Aajoda Testimonials < 2.2.2 - Cross-Site Scripting | 346755 , 377360 |
| CVE-2023-2224 | Seo By 10Web < 1.2.7 - Cross-Site Scripting | 377360 |
| CVE-2022-2546 | WordPress All-in-One WP Migration <=7.62 - Cross-Site Scripting | 377360 |
| CVE-2024-13627 | OWL Carousel Slider - Cross-Site Scripting | 341266 , 346755 , 377360 |
| CVE-2022-29495 | WordPress Popup Builder <= 4.1.11 - Cross-Site Request Forgery | 345490 , 377360 |
| CVE-2021-25075 | WordPress Duplicate Page or Post <1.5.1 - Cross-Site Scripting | 346755 , 377360 |