Atomicorp WAF Research Notes

Research Update - 2026-09-14

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-18080ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM351000
CVE-2026-2942ProSolution WP Client <= 1.9.9 - Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess351000
CVE-2026-3535DSGVO Google Web Fonts GDPR <= 1.1 - Unauthenticated Arbitrary File Upload via 'fonturl' Parameter351000
CVE-2026-4885Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload351000
CVE-2026-83627Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-8778MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload351000
CVE-2026-3141FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter340007 , 344360 , 347009 , 390709
CVE-2026-14357DevKit Pro <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Ex340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 360029
CVE-2026-14498Query Wrangler <= 1.5.57 - Authenticated (Subscriber+) Remote Code Execution via 'options' Parameter340014 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 360029
CVE-2026-15965MaxUpload <= 1.4.0 - Unauthenticated Arbitrary File Upload via 'resumableFilename' Parameter351000
CVE-2026-18438Templately <= 3.7.1 - Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Im351000
CVE-2026-6147LightSync Pro <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload351000
CVE-2026-76801FireBox <= 3.1.10 - Authenticated (Author+) Remote Code Execution to Privilege Escalation340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-8365Blocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614
CVE-2026-10818WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering351000
CVE-2026-19942Atarim <= 5.1.1 - Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10207PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id' Parameter340017 , 340144 , 340156 , 340157 , 380122
CVE-2026-10737SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthenticated Arbitrary File Information Disclosure v340748 , 344360 , 347006 , 390709
CVE-2026-14490Demi <= 0.0.6 - Unauthenticated Arbitrary Directory Deletion via demi_restore_step AJAX action340748 , 344360 , 347006 , 347009 , 390709
CVE-2026-15162Object Sync for Salesforce <= 2.2.13 - Unauthenticated SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-15918VikAppointments – Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-18352User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter340007 , 344360 , 347009 , 390709
CVE-2026-18881TableOn <= 1.0.5.1 - Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-18983One User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-3985Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Unauthenticated SQL Injection via 'checkout_uu340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-13359Contact Form to DB by BestWebSoft <= 1.7.5 - Unauthenticated Stored Cross-Site Scripting via cntctfrm_contact_dropdown P340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-13425Database for CF7 <= 1.2.6 - Unauthenticated Stored Cross-Site Scripting via Array Form Field Values333140 , 333141 , 340095 , 346755 , 350147 , 350148
CVE-2026-13440StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Unau346755
CVE-2026-15401VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Pa333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-15780WP Statistics <= 14.16.8 - Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-16143VikRentItems Flexible Rental Management System <= 1.2.1 - Unauthenticated Stored Cross-Site Scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 346755 , 350147 , 350148
CVE-2026-17506Independent Analytics <= 2.15.0 - Unauthenticated Stored Cross-Site Scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-5934WP Rocket <= 3.21.0.1 - Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpo340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-6020ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-7534SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-75528Broken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-7693Backup Migration <= 2.1.5.1 - Authenticated (Administrator+) OS Command Injection via 'file' Parameter340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-83625Contact Form by Supsystic <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via IP Address Header333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-14280Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys340748 , 344360 , 347006
CVE-2026-11977WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-13119Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' Parameter340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-15761Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filter' Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-16087Icegram Engage <= 3.1.42 - Authenticated (Contributor+) Second-Order SQL Injection via 'messages[][id]' Parameter340156
CVE-2026-6251Chaty Pro <= 3.5.5 - Authenticated (Subscriber+) SQL Injection via 'widget_id' Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-7542Slider Revolution 7.0 - 7.0.10 - Authenticated (Subscriber+) Sensitive Information Disclosure340007 , 344360 , 347009 , 390709
CVE-2026-8685Infility Global <= 2.15.16 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9829Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Par340016 , 340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-0552Simple Shopping Cart <= 5.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsc_display_product' Shor333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-0626WPFunnels <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpf_optin_form' Shortcode333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-13203Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_id' Shortcode Attribute333140 , 340087 , 340095 , 340099 , 340147 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-15446EWWW Image Optimizer <= 8.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-script' Lazy Load Att333140 , 333141 , 342259
CVE-2026-16786Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_testimonials_output S333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-16788Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_projects_output Short333140 , 333141 , 340095 , 342259
CVE-2026-18400Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'delay'333140 , 333141 , 340095 , 340147 , 340148 , 346755
CVE-2026-18488Blocksy Companion <= 2.1.51 - Authenticated (Author+) Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-5092Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-5391LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-6454Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' At333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-6565Style Kits – Advanced Theme Styles for Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-8791Booking System Trafft <= 1.0.17 - Authenticated (Subscriber+) Stored Cross-Site Scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-8977WP GDPR Cookie Consent <= 1.0.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ninja_gdpr_ajax_actions'340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-9281Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'jtlma_custom_js' Page Se340087 , 340099 , 341099 , 341266 , 346755
CVE-2023-51769Frappe Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-11603Product Filter Widget for Elementor <= 1.0.6 - Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter346755
CVE-2026-18843Beaver Builder Plugin (Pro Version) <= 2.11.0.1 - Reflected Cross-Site Scripting via 'no_results_message' node_preview P333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 346755
CVE-2026-4246ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-8626SponsorMe <= 0.5.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-90617GH05TCREW PentestAgent MCP HTTP Server main.py run_task os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-906190x4m4 HexStrike AI Execute Endpoint hexstrike_server.py os command injection340014 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-906900x4m4 HexStrike AI API Tools Endpoint hexstrike_server.py subprocess.Popen os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-906910x4m4 HexStrike AI API Files Endpoint hexstrike_server.py FileOperationsManager path traversal344360 , 390709
CVE-2024-23176MassMessage Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-6394Nexa Blocks <= 1.1.1 - Unauthenticated Blind Server-Side Request Forgery via 'demo_json_file' Parameter337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-3835Prevent Direct Access – Protect WordPress Files <= 2.8.8.8 - Unauthenticated Protected File Access340007 , 344360 , 347009 , 390709
CVE-2026-17604Kirki <= 6.1.1 - Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter347009 , 381206
CVE-2026-5062PrettyLinks <= 3.6.20 - Authenticated (Administrator+) SQL Injection via 's' Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-5114SpeedyCache <= 1.3.8 - Authenticated (Administrator+) Arbitrary File Read340007 , 344360 , 347009 , 390709
CVE-2026-77823LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-4406Gravity Forms <= 2.9.30 - Reflected Cross-Site Scripting via 'form_ids' Parameter340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-10100Simple Custom Login Page <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-12905Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Refere340007 , 344360 , 347009 , 390709
CVE-2026-38924Serena Security Vulnerability340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-90615SourceCodester Class and Exam Timetabling System subject1.php cross site scripting333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755