Vulnerabilidades en wedevs
110 resultadosAnálisis Vexday
A WEDevs apresenta 50 vulnerabilidades catalogadas, com 13 descobertas nos últimos 90 dias, indicando atividade contínua. Nenhuma das vulnerabilidades está sob ataque ativo (KEV), e apenas 1 é classificada como crítica, reduzindo o risco imediato. A injeção SQL (CWE-89) é a fraqueza predominante, sugerindo falhas em validação de entrada que demandam remediação prioritária.
CVE-2024-0608MEDIUMWP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Authenticated (Subscriber+) SQL InjectionEPSS 0.5%CVE-2023-6632MEDIUMHappy Addons for Elementor <= 3.9.1.1 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2024-0956MEDIUMWP ERP <= 1.13.0 - Authenticated (AccountingManager+) SQL InjectionEPSS 0.5%CVE-2024-0609HIGHWP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.5%CVE-2024-6666HIGHWP ERP <= 1.13.0 - Authenticated (Accounting Manager+) SQL Injection via vendor_idEPSS 0.5%CVE-2024-12015HIGHSQL Injection in WordPress Project Manager PluginEPSS 0.5%CVE-2024-13752MEDIUMWP Project Manager <= 2.6.17 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options UpdateEPSS 0.5%CVE-2023-1844MEDIUMSubscribe2 <= 10.40 - Missing AuthorizationEPSS 0.5%CVE-2023-40003MEDIUMWordPress WP Project Manager plugin <= 2.6.7 - Broken Access Control vulnerabilityEPSS 0.5%CVE-2026-81283HIGHWordPress WP User Frontend plugin <= 4.3.10 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2026-15349MEDIUMERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX HandlerEPSS 0.5%CVE-2026-12077HIGHDokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longitude' ParametersEPSS 0.5%CVE-2023-34008HIGHWordPress WP ERP Plugin <= 1.12.3 is vulnerable to Cross Site Scripting (XSS)EPSS 0.5%CVE-2020-36735MEDIUMWP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.6.3 - Cross-Site Request Forgery BypassEPSS 0.5%CVE-2026-13011MEDIUMERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support <= 1.17.5 - Authenticated (HR Manager+) SQL Injection via 'orderby' ParameterEPSS 0.5%CVE-2026-12224HIGHDokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST EndpointEPSS 0.4%CVE-2020-36745MEDIUMWP Project Manager <= 2.4.0 - Cross-Site Request Forgery BypassEPSS 0.4%CVE-2024-38693HIGHWordPress WP User Frontend plugin <= 4.0.7 - SQL Injection vulnerabilityEPSS 0.4%CVE-2025-5931HIGHDokan Pro <= 4.0.5 - Authenticated (Vendor+) Privilege EscalationEPSS 0.4%CVE-2024-12195MEDIUMWP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 - Authenticated (Subscriber+) SQL InjectionEPSS 0.4%