Atomicorp WAF Research Notes

Research Update - 2026-08-12

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2025-47577TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File Upload382238
CVE-2014-8739WordPress Sexy Contact Form (<= 0.9.7) - Arbitrary File Upload300016
CVE-2015-9499WordPress ShowBiz Pro <= 1.7.1 - Authenticated Arbitrary File Upload to RCE300019 , 300029
CVE-2020-12800WordPress Contact Form 7 <1.3.3.3 - Remote Code Execution300018
CVE-2020-12832WordPress Simple File List - Path Traversal382238
CVE-2022-1952WordPress eaSYNC Booking <1.1.16 - Arbitrary File Upload382238
CVE-2022-3982WordPress Booking Calendar <3.2.2 - Arbitrary File Upload382238
CVE-2023-4596WordPress Plugin Forminator 1.24.6 - Arbitrary File Upload300006
CVE-2023-4634Media Library Assistant < 3.09 - Remote Code Execution/Local File Inclusion300017
CVE-2023-51409Jordy Meow AI Engine - Unrestricted File Upload382238
CVE-2023-5360WordPress Royal Elementor Addons Plugin <= 1.3.78 - Arbitrary File Upload382238
CVE-2023-6553Worpress Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution301106
CVE-2024-8425WooCommerce Ultimate Gift Card ≤ 2.6.0 - Arbitrary File Upload382238
CVE-2026-0740Ninja Forms File Uploads <= 3.3.26 - Arbitrary File Upload382238
CVE-2026-10580Hippoo Mobile App for WooCommerce <= 1.9.4 - Authentication Bypass to Admin Account Takeover320008 , 330919
CVE-2026-1492WordPress User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation300020
CVE-2026-3300Everest Forms Pro <= 1.9.12 - Unauthenticated RCE via Calculation Formula Injection300021
CVE-2026-3584WordPress Kali Forms <= 2.4.9 - Remote Code Execution300223
CVE-2026-5718Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Execution382238
CVE-2015-9480WordPress RobotCPA 5 - Directory Traversal320006
CVE-2026-5073WordPress ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection320011
CVE-2026-9290WP User Manager – User Profile Builder & Membership - Local File Inclusion320017