Vulnerabilidades en weDevs
110 resultadosAnálisis Vexday
weDevs acumula 44 vulnerabilidades no histórico, com 6 divulgadas nos últimos 90 dias, indicando desenvolvimento contínuo de riscos. Nenhuma vulnerabilidade crítica foi registrada e não há evidência de exploração ativa em ambientes capturados, reduzindo a urgência imediata. A fraqueza predominante é controle de acesso inadequado (CWE-862), sugerindo problemas estruturais de autorização que merecem atenção em avaliações de segurança.
CVE-2026-13011MEDIUMERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support <= 1.17.5 - Authenticated (HR Manager+) SQL Injection via 'orderby' ParameterEPSS 0.5%CVE-2026-12224HIGHDokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST EndpointEPSS 0.4%CVE-2020-36745MEDIUMWP Project Manager <= 2.4.0 - Cross-Site Request Forgery BypassEPSS 0.4%CVE-2024-38693HIGHWordPress WP User Frontend plugin <= 4.0.7 - SQL Injection vulnerabilityEPSS 0.4%CVE-2025-5931HIGHDokan Pro <= 4.0.5 - Authenticated (Vendor+) Privilege EscalationEPSS 0.4%CVE-2024-12195MEDIUMWP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 - Authenticated (Subscriber+) SQL InjectionEPSS 0.4%CVE-2024-8739MEDIUMReCaptcha Integration for WordPress <= 1.2.5 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2024-13500MEDIUMWP Project Manager <= 2.6.17 - Authenticated (Subscriber+) SQL Injection via orderby ParameterEPSS 0.4%CVE-2026-12418MEDIUMUser Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' ParameterEPSS 0.4%CVE-2026-13110MEDIUMStoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX ActionEPSS 0.4%CVE-2025-47540MEDIUMWordPress weMail plugin <= 1.14.13 - Sensitive Data Exposure VulnerabilityEPSS 0.4%CVE-2024-10548MEDIUMWP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST APIEPSS 0.4%CVE-2023-49860MEDIUMWordPress WP Project Manager Plugin <= 2.6.7 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2024-34822MEDIUMWordPress weMail plugin <= 1.14.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-32485HIGHWordPress WP User Frontend plugin <= 4.2.8 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-78470MEDIUMWP Project Manager Pro <= 4.0.1 - Authenticated (Subscriber+) SQL InjectionEPSS 0.4%CVE-2026-12079MEDIUMDokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' ParameterEPSS 0.4%CVE-2024-34442MEDIUMWordPress weDocs plugin <= 2.1.4 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-14574MEDIUMweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.1.15 - Unauthenticated Sensitive Information ExposureEPSS 0.4%CVE-2026-31917HIGHWordPress WP ERP plugin <= 1.16.10 - SQL Injection vulnerabilityEPSS 0.4%