Atomicorp WAF Research Notes

Research Update - 2026-07-21

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2017-18580WordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Execution377360
CVE-2021-24215Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalation377360
CVE-2021-34621WordPress ProfilePress 3.0.0-3.1.3 - Admin User Creation Weakness377360
CVE-2021-4449ZoomSounds Plugin - Unauthenticated Arbitrary File Upload392301
CVE-2023-33831FUXA - Unauthenticated Remote Code Execution340095 , 344370 , 345240 , 380026
CVE-2024-3605WP Hotel Booking <= 2.1.0 - SQL Injection341245 , 380026 , 380122
CVE-2024-37843Craft CMS <=v3.7.31 - SQL Injection344378
CVE-2025-11833Post SMTP <= 3.6.0 - Email Log Disclosure377360
CVE-2025-1562Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Control377360
CVE-2025-54782NestJS DevTools Integration - Remote Code Execution345240
CVE-2026-41940cPanel & WHM - Authentication Bypass via Session-File CRLF Injection377364
CVE-2024-8673Z-Downloads < 1.11.7 - Cross-Site Scripting377360
CVE-2025-49029WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code Execution377360
CVE-2025-1302JSONPath Plus < 10.3.0 - Remote Code Execution345240 , 346755 , 360151 , 380026
CVE-2020-9043WordPress wpCentral <1.5.1 - Information Disclosure377360
CVE-2021-24347WordPress SP Project & Document Manager <4.22 - Authenticated Shell Upload377360
CVE-2021-25082WordPress Popup Builder < 4.0.7 - Remote Code Execution340162 , 340165 , 377360 , 390904 , 398007
CVE-2022-0439Email Subscribers & Newsletters <= 5.3.1 - Authenticated SQL Injection340016 , 377360 , 380122
CVE-2022-1329Elementor Website Builder - Remote Code Execution377360
CVE-2023-23897Ozette Plugins - Cross-Site Request Forgery345490 , 377360
CVE-2023-48777WordPress Elementor 3.18.1 - File Upload/Remote Code Execution377360
CVE-2025-2075Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation377360
CVE-2012-10018WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Authenticated Stored XSS via SVG File Upload346755 , 377360
CVE-2018-1335Apache Tika < 1.1.8 - Header Command Injection340138 , 391213
CVE-2020-36836WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletion340748 , 347006 , 377360
CVE-2021-24170User Profile Picture < 2.5.0 - Sensitive Information Disclosure377360
CVE-2021-24644Images to WebP < 1.9 - Authenticated Local File Inclusion340007 , 377360
CVE-2024-45293TablePress < 2.4.3 - XXE Injection377360
CVE-2026-9282W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read336461 , 344360
CVE-2021-24155WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload377360
CVE-2021-24970WordPress All-In-One Video Gallery <2.5.0 - Local File Inclusion377360
CVE-2023-0900AP Pricing Tables Lite <= 1.1.6 - SQL Injection377360
CVE-2023-47873WordPress WP Child Theme Generator < 1.1.3 - Arbitrary File Upload377360
CVE-2025-5961WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload377360
CVE-2024-10152Simple Certain Time to Show Content - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-12638Bulk Me Now! Plugin <= 2.0 - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-12749WordPress Competition Form Plugin <= 2.0 - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-12878Lazy Blocks <= 3.8.2 - Cross-Site Scripting340148 , 341266 , 346755 , 377360
CVE-2024-13055Dyn Business Panel Plugin <= 1.0.0 - Cross-Site Scripting341266 , 377360
CVE-2024-13094WP Triggers Lite - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-13330JustRows WordPress - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-13569WordPress Front End Users - Reflected XSS341266 , 377360
CVE-2015-2755WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scripting346755 , 377360
CVE-2020-8615Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery345490 , 377360
CVE-2022-1398External Media without Import <=1.1.2 - Authenticated Blind Server-Side Request Forgery377360
CVE-2023-3345LMS by Masteriyo < 1.6.8 - Information Exposure377360
CVE-2024-9765EKC Tournament Manager WordPress plugin - Path Traversal344360 , 347009 , 377360
CVE-2025-13652WordPress CBX Bookmark & Favorite Plugin <= 2.0.4 - SQL Injection340016 , 377360 , 380122
CVE-2025-13418Responsive Pricing Table <= 5.1.12 - Cross-Site Scripting346755 , 377360
CVE-2015-8350WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS340148 , 341266 , 346755 , 377360
CVE-2020-36731Flexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Update346755 , 377360 , 390585
CVE-2021-24165WordPress Ninja Forms <3.4.34 - Open Redirect377360
CVE-2021-24213GiveWP <= 2.9.7 - Cross-Site Scripting340148 , 341266 , 346755 , 377360
CVE-2021-24286WordPress Plugin Redirect 404 to Parent 1.3.0 - Cross-Site Scripting346755 , 377360
CVE-2021-24287WordPress Select All Categories and Taxonomies <1.3.2 - Cross-Site Scripting346755 , 377360
CVE-2021-24452WordPress W3 Total Cache <2.1.5 - Cross-Site Scripting346755 , 377360
CVE-2021-24657Limit Login Attempts WordPress - Stored Cross-site Scripting377360
CVE-2021-24876Registrations for The Events Calendar < 2.7.5 - Authenticated Reflected Cross-Site Scripting346755 , 347198 , 377360
CVE-2022-0189WordPress RSS Aggregator < 4.20 - Authenticated Cross-Site Scripting346755 , 377360
CVE-2023-0514Membership Database <= 1.0 - Cross-Site Scripting346755 , 377360
CVE-2023-2272Tiempo.com <= 0.1.2 - Cross-Site Scripting377360
CVE-2023-37979Ninja Forms < 3.6.26 - Cross-Site Scripting346755 , 377360
CVE-2024-12732AffiliateImporterEb <= 1.0.6 - Reflected XSS341266 , 346755 , 377360
CVE-2024-12734Advance Post Prefix WordPress plugin - Reflected XSS341266 , 377360
CVE-2024-12737WP BASE Booking - Reflected XSS341266 , 346755 , 377360
CVE-2024-12873Custom Field Manager WordPress - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-13112WP MediaTagger <= 4.1.1 - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-13114WP Projects Portfolio <= 3.0 - Cross-Site Scripting340148 , 341266 , 346755 , 377360
CVE-2024-13219Privacy Policy Genius - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-13220WordPress Google Map Professional - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-13221Fantastic ElasticSearch Plugin <= 4.1.0 - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-13224SlideDeck 1 Lite Content Slider - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-13225ECT Home Page Products - Reflected XSS341266 , 346755 , 377360
CVE-2024-13226A5 Custom Login Page - Reflected XSS341266 , 346755 , 377360
CVE-2024-13325Glossy WordPress - Reflected XSS341266 , 377360
CVE-2024-13326iBuildApp <= 0.2.0 - Reflected Cross-Site Scripting341266 , 377360
CVE-2024-13327Musicbox WordPress - Reflected XSS341266 , 346755 , 377360
CVE-2024-13331WP Dream Carousel < 1.0.1b - Cross-Site Scripting340148 , 341266 , 346755 , 377360
CVE-2024-13492Guten Free Options - Cross Site Scripting341266 , 377360
CVE-2024-13543Zarinpal Paid Download - Reflected XSS341266 , 346755 , 377360
CVE-2024-13570WordPress Stray Random Quotes <= 1.9.9 - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-13619LifterLMS < 8.0.1 - Cross-Site Scripting340148 , 341266 , 346755 , 377360
CVE-2024-13628WP Pricing Table - Reflected XSS341266 , 346755 , 377360
CVE-2024-13630NewsTicker <= 1.0 - Reflected Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-13634Post Sync Plugin <= 1.1 - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-29138WordPress Restrict User Access <= 2.5 - Cross-Site Scripting346755 , 377360
CVE-2024-29792Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scripting346755 , 347198 , 377360
CVE-2024-30194Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scripting333141 , 340149 , 344361 , 344364 , 346755 , 347198 , 377360
CVE-2024-37261WP-Lister Lite for Amazon <= 2.6.16 - Cross-Site Scripting346755 , 377360
CVE-2024-39646WordPress Custom 404 Pro <= 3.11.1 - Reflected XSS346755 , 347198 , 377360
CVE-2024-43971Sunshine Photo Cart <= 3.2.5 - Reflected Cross-Site Scripting344361 , 344364 , 347198 , 377360
CVE-2024-4439WordPress Core <6.5.2 - Cross-Site Scripting377360
CVE-2024-4455YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site Scripting377360
CVE-2024-6753Social Auto Poster <= 5.3.14 - Stored Cross-Site Scripting377360
CVE-2025-4652Broadstreet WordPress plugin - Reflected XSS340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 377360
CVE-2026-1296Frontend Post Submission Manager Lite <= 1.2.7 - Open Redirect377360
CVE-2017-8295WordPress Core < 4.7.4 - Unauthorized Password Reset377360
CVE-2017-14725WordPress < 4.8.2 - Authenticated Open Redirect377360
CVE-2017-17092WordPress < 4.9.1 - Authenticated JavaScript File Upload377360
CVE-2018-16363WordPress File Manager < 3.0 - Cross-Site Scripting341266 , 346755 , 377360
CVE-2021-33851WordPress Customize Login Image <3.5.3 - Cross-Site Scripting377360
CVE-2021-36873WordPress iQ Block Country <=1.2.11 - Cross-Site Scripting377360
CVE-2022-0765WordPress Loco Translate < 2.6.1 - Cross-Site Scripting377360
CVE-2022-3506WordPress Related Posts <2.1.3 - Stored Cross-Site Scripting377360
CVE-2023-7246System Dashboard < 2.8.10 - Cross-Site Scripting377360
CVE-2024-10146Simple File List < 6.1.13 - Reflected Cross-Site Scripting340087 , 341266 , 346755 , 377360
CVE-2024-13097WP Finance Plugin <= 1.3.6 - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-13098WordPress Email Newsletter - Reflected XSS341266 , 346755 , 377360
CVE-2024-13099Widget4Call WordPress - Cross-Site Scripting341266 , 346755 , 377360
CVE-2024-2473WPS Hide Login <= 1.9.15.2 - Login Page Disclosure377360
CVE-2022-2863WordPress WPvivid Backup <0.9.76 - Local File Inclusion377360
CVE-2024-10708System Dashboard < 2.8.15 - Admin+ Path Traversal336461 , 344360 , 377360 , 381206
CVE-2021-24681Duplicate Page WordPress - Stored Cross-Site Scripting377360
CVE-2022-0535WordPress E2Pdf <1.16.45 - Cross-Site Scripting377360
CVE-2022-0873WordPress Gmedia Photo Gallery Plugin < 1.20.0 - Cross-Site Scripting377360
CVE-2022-1029Limit Login Attempts - Stored Cross-Site Scripting377360
CVE-2022-4260WordPress WP-Ban <1.69.1 - Stored Cross-Site Scripting377360
CVE-2023-2009Pretty Url <= 1.5.4 - Cross-Site Scripting377360
CVE-2023-2178Aajoda Testimonials < 2.2.2 - Cross-Site Scripting346755 , 377360
CVE-2023-2224Seo By 10Web < 1.2.7 - Cross-Site Scripting377360
CVE-2022-2546WordPress All-in-One WP Migration <=7.62 - Cross-Site Scripting377360
CVE-2024-13627OWL Carousel Slider - Cross-Site Scripting341266 , 346755 , 377360
CVE-2022-29495WordPress Popup Builder <= 4.1.11 - Cross-Site Request Forgery345490 , 377360
CVE-2021-25075WordPress Duplicate Page or Post <1.5.1 - Cross-Site Scripting346755 , 377360