Atomicorp WAF Research Notes
Research Update - 2026-08-12
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2025-47577 | TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File Upload | 382238 |
| CVE-2014-8739 | WordPress Sexy Contact Form (<= 0.9.7) - Arbitrary File Upload | 300016 |
| CVE-2015-9499 | WordPress ShowBiz Pro <= 1.7.1 - Authenticated Arbitrary File Upload to RCE | 300019 , 300029 |
| CVE-2020-12800 | WordPress Contact Form 7 <1.3.3.3 - Remote Code Execution | 300018 |
| CVE-2020-12832 | WordPress Simple File List - Path Traversal | 382238 |
| CVE-2022-1952 | WordPress eaSYNC Booking <1.1.16 - Arbitrary File Upload | 382238 |
| CVE-2022-3982 | WordPress Booking Calendar <3.2.2 - Arbitrary File Upload | 382238 |
| CVE-2023-4596 | WordPress Plugin Forminator 1.24.6 - Arbitrary File Upload | 300006 |
| CVE-2023-4634 | Media Library Assistant < 3.09 - Remote Code Execution/Local File Inclusion | 300017 |
| CVE-2023-51409 | Jordy Meow AI Engine - Unrestricted File Upload | 382238 |
| CVE-2023-5360 | WordPress Royal Elementor Addons Plugin <= 1.3.78 - Arbitrary File Upload | 382238 |
| CVE-2023-6553 | Worpress Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution | 301106 |
| CVE-2024-8425 | WooCommerce Ultimate Gift Card ≤ 2.6.0 - Arbitrary File Upload | 382238 |
| CVE-2026-0740 | Ninja Forms File Uploads <= 3.3.26 - Arbitrary File Upload | 382238 |
| CVE-2026-10580 | Hippoo Mobile App for WooCommerce <= 1.9.4 - Authentication Bypass to Admin Account Takeover | 320008 , 330919 |
| CVE-2026-1492 | WordPress User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation | 300020 |
| CVE-2026-3300 | Everest Forms Pro <= 1.9.12 - Unauthenticated RCE via Calculation Formula Injection | 300021 |
| CVE-2026-3584 | WordPress Kali Forms <= 2.4.9 - Remote Code Execution | 300223 |
| CVE-2026-5718 | Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Execution | 382238 |
| CVE-2015-9480 | WordPress RobotCPA 5 - Directory Traversal | 320006 |
| CVE-2026-5073 | WordPress ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection | 320011 |
| CVE-2026-9290 | WP User Manager – User Profile Builder & Membership - Local File Inclusion | 320017 |