Atomicorp WAF Research Notes
Research Update - 2026-09-14
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-18080 | ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM | 351000 |
| CVE-2026-2942 | ProSolution WP Client <= 1.9.9 - Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess | 351000 |
| CVE-2026-3535 | DSGVO Google Web Fonts GDPR <= 1.1 - Unauthenticated Arbitrary File Upload via 'fonturl' Parameter | 351000 |
| CVE-2026-4885 | Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload | 351000 |
| CVE-2026-83627 | Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-8778 | MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload | 351000 |
| CVE-2026-3141 | FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-14357 | DevKit Pro <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Ex | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 360029 |
| CVE-2026-14498 | Query Wrangler <= 1.5.57 - Authenticated (Subscriber+) Remote Code Execution via 'options' Parameter | 340014 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 360029 |
| CVE-2026-15965 | MaxUpload <= 1.4.0 - Unauthenticated Arbitrary File Upload via 'resumableFilename' Parameter | 351000 |
| CVE-2026-18438 | Templately <= 3.7.1 - Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Im | 351000 |
| CVE-2026-6147 | LightSync Pro <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload | 351000 |
| CVE-2026-76801 | FireBox <= 3.1.10 - Authenticated (Author+) Remote Code Execution to Privilege Escalation | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-8365 | Blocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy | 340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 |
| CVE-2026-10818 | WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering | 351000 |
| CVE-2026-19942 | Atarim <= 5.1.1 - Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-10207 | PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id' Parameter | 340017 , 340144 , 340156 , 340157 , 380122 |
| CVE-2026-10737 | SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthenticated Arbitrary File Information Disclosure v | 340748 , 344360 , 347006 , 390709 |
| CVE-2026-14490 | Demi <= 0.0.6 - Unauthenticated Arbitrary Directory Deletion via demi_restore_step AJAX action | 340748 , 344360 , 347006 , 347009 , 390709 |
| CVE-2026-15162 | Object Sync for Salesforce <= 2.2.13 - Unauthenticated SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-15918 | VikAppointments – Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-18352 | User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-18881 | TableOn <= 1.0.5.1 - Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter | 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2026-18983 | One User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-3985 | Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Unauthenticated SQL Injection via 'checkout_uu | 340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2026-13359 | Contact Form to DB by BestWebSoft <= 1.7.5 - Unauthenticated Stored Cross-Site Scripting via cntctfrm_contact_dropdown P | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-13425 | Database for CF7 <= 1.2.6 - Unauthenticated Stored Cross-Site Scripting via Array Form Field Values | 333140 , 333141 , 340095 , 346755 , 350147 , 350148 |
| CVE-2026-13440 | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Unau | 346755 |
| CVE-2026-15401 | VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Pa | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-15780 | WP Statistics <= 14.16.8 - Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-16143 | VikRentItems Flexible Rental Management System <= 1.2.1 - Unauthenticated Stored Cross-Site Scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 346755 , 350147 , 350148 |
| CVE-2026-17506 | Independent Analytics <= 2.15.0 - Unauthenticated Stored Cross-Site Scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-5934 | WP Rocket <= 3.21.0.1 - Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpo | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-6020 | ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-7534 | SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-75528 | Broken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log | 333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-7693 | Backup Migration <= 2.1.5.1 - Authenticated (Administrator+) OS Command Injection via 'file' Parameter | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-83625 | Contact Form by Supsystic <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via IP Address Header | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-14280 | Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys | 340748 , 344360 , 347006 |
| CVE-2026-11977 | WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-13119 | Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' Parameter | 340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2026-15761 | Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filter' Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-16087 | Icegram Engage <= 3.1.42 - Authenticated (Contributor+) Second-Order SQL Injection via 'messages[][id]' Parameter | 340156 |
| CVE-2026-6251 | Chaty Pro <= 3.5.5 - Authenticated (Subscriber+) SQL Injection via 'widget_id' Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-7542 | Slider Revolution 7.0 - 7.0.10 - Authenticated (Subscriber+) Sensitive Information Disclosure | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-8685 | Infility Global <= 2.15.16 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9829 | Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Par | 340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2026-0552 | Simple Shopping Cart <= 5.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsc_display_product' Shor | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-0626 | WPFunnels <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpf_optin_form' Shortcode | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-13203 | Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_id' Shortcode Attribute | 333140 , 340087 , 340095 , 340099 , 340147 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-15446 | EWWW Image Optimizer <= 8.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Att | 333140 , 333141 , 342259 |
| CVE-2026-16786 | Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_testimonials_output S | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-16788 | Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_projects_output Short | 333140 , 333141 , 340095 , 342259 |
| CVE-2026-18400 | Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay' | 333140 , 333141 , 340095 , 340147 , 340148 , 346755 |
| CVE-2026-18488 | Blocksy Companion <= 2.1.51 - Authenticated (Author+) Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-5092 | Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-5391 | LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-6454 | Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' At | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-6565 | Style Kits – Advanced Theme Styles for Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-8791 | Booking System Trafft <= 1.0.17 - Authenticated (Subscriber+) Stored Cross-Site Scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-8977 | WP GDPR Cookie Consent <= 1.0.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ninja_gdpr_ajax_actions' | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-9281 | Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'jtlma_custom_js' Page Se | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2023-51769 | Frappe Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-11603 | Product Filter Widget for Elementor <= 1.0.6 - Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter | 346755 |
| CVE-2026-18843 | Beaver Builder Plugin (Pro Version) <= 2.11.0.1 - Reflected Cross-Site Scripting via 'no_results_message' node_preview P | 333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 346755 |
| CVE-2026-4246 | ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-8626 | SponsorMe <= 0.5.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-90617 | GH05TCREW PentestAgent MCP HTTP Server main.py run_task os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-90619 | 0x4m4 HexStrike AI Execute Endpoint hexstrike_server.py os command injection | 340014 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-90690 | 0x4m4 HexStrike AI API Tools Endpoint hexstrike_server.py subprocess.Popen os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-90691 | 0x4m4 HexStrike AI API Files Endpoint hexstrike_server.py FileOperationsManager path traversal | 344360 , 390709 |
| CVE-2024-23176 | MassMessage Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-6394 | Nexa Blocks <= 1.1.1 - Unauthenticated Blind Server-Side Request Forgery via 'demo_json_file' Parameter | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-3835 | Prevent Direct Access – Protect WordPress Files <= 2.8.8.8 - Unauthenticated Protected File Access | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-17604 | Kirki <= 6.1.1 - Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter | 347009 , 381206 |
| CVE-2026-5062 | PrettyLinks <= 3.6.20 - Authenticated (Administrator+) SQL Injection via 's' Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-5114 | SpeedyCache <= 1.3.8 - Authenticated (Administrator+) Arbitrary File Read | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-77823 | LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-4406 | Gravity Forms <= 2.9.30 - Reflected Cross-Site Scripting via 'form_ids' Parameter | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-10100 | Simple Custom Login Page <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-12905 | Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Refere | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-38924 | Serena Security Vulnerability | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-90615 | SourceCodester Class and Exam Timetabling System subject1.php cross site scripting | 333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 |