Skip to main content

Vendor archive

wedevs CVEs

Beta · best-effort

48 CVEs tagged to vendor wedevs1 Critical, 17 High, 30 Medium, 0 Low, 0 Unrated.

CVE-2024-12812

Published May 15, 2025

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can ma…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12808

Published May 15, 2025

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and escape some of its settings,…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47540

Published May 7, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail wemail allows Retrieve Embedded Sensitive Data.This issue affects weMail:…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2541

Published Apr 11, 2025

The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient inpu…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3100

Published Apr 9, 2025

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SV…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32280

Published Apr 4, 2025

Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Request Forgery.This issue affects WP Project Manager: from n…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22649

Published Mar 27, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-13500

Published Feb 15, 2025

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13752

Published Feb 15, 2025

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12852

Published Jan 8, 2025

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12195

Published Jan 4, 2025

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id'…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45765

Published Jan 2, 2025

Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.1…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-10548

Published Dec 19, 2024

The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40003

Published Dec 13, 2024

Missing Authorization vulnerability in weDevs WP Project Manager wedevs-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-10520

Published Nov 20, 2024

The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', '…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10174

Published Nov 13, 2024

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference i…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8739

Published Nov 2, 2024

The ReCaptcha Integration for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the UR…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47640

Published Oct 29, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP ERP erp allows Reflected XSS.This issue affects WP ERP: from n/a th…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8801

Published Sep 25, 2024

The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. T…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38693

Published Aug 29, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Front…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43238

Published Aug 18, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows DOM-Based XSS.This issue affects weMail: from n/a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6666

Published Jul 11, 2024

The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all versions up to, and including, 1.13.0 due to insufficient escaping…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5790

Published Jun 29, 2024

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient Heading widget in all version…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34822

Published Jun 11, 2024

Missing Authorization vulnerability in weDevs weMail.This issue affects weMail: from n/a through 1.14.2.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52217

Published Jun 11, 2024

Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 48 CVEsPage 1 of 2