Vulnerabilidades em WeDevs

100 resultados
Análise Vexday

WeDevs apresenta perfil de risco baixo com apenas 1 CVE registrado na base, nenhum sob exploração ativa conhecida e sem criticidade máxima associada. A vulnerabilidade identificada refere-se a injeção SQL (CWE-89), fraqueza clássica que requer atenção, mas não há evidência de exploração em campo nem publicações recentes que indiquem urgência imediata.

CVE-2024-37946MEDIUMWordPress ReCaptcha Integration for WordPress plugin <= 1.2.7 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2026-4834HIGHWP ERP Pro <= 1.5.1 - Unauthenticated SQL Injection via 'search_key' ParameterEPSS 0.3%CVE-2026-12077HIGHDokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longitude' ParametersEPSS 0.3%CVE-2026-15349MEDIUMERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX HandlerEPSS 0.3%CVE-2025-8994MEDIUMWP Project Manager <= 2.6.26 - Authenticated (Subscriber+) SQL Injection via 'completed_at_operator'EPSS 0.3%CVE-2025-58269MEDIUMWordPress WP Project Manager Plugin <= 2.6.25 - Sensitive Data Exposure VulnerabilityEPSS 0.3%CVE-2025-14348MEDIUMweMail <= 2.0.7 - Insufficient Authorization via x-wemail-user Header to Sensitive Information DisclosureEPSS 0.3%CVE-2026-13440HIGHStoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'message_popup' ParameterEPSS 0.3%CVE-2025-13921MEDIUMweDocs <= 2.1.16 - Missing Authorization to Authenticated (Subscriber+) Documentation Post UpdateEPSS 0.3%CVE-2025-3100MEDIUMWP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File UploadEPSS 0.3%CVE-2025-14339MEDIUMweMail <= 2.0.7 - Missing Authorization to Unauthenticated Form DeletionEPSS 0.3%CVE-2026-32485HIGHWordPress WP User Frontend plugin <= 4.2.8 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-13011MEDIUMERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support <= 1.17.5 - Authenticated (HR Manager+) SQL Injection via 'orderby' ParameterEPSS 0.3%CVE-2026-15411MEDIUMStoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Options Update via create_popup AJAX ActionEPSS 0.3%CVE-2025-22649MEDIUMWordPress WP Project Manager plugin <= 2.6.22 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-58672MEDIUMWordPress WP User Frontend Plugin <= 4.1.12 - Broken Access Control VulnerabilityEPSS 0.2%CVE-2026-12418MEDIUMUser Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' ParameterEPSS 0.2%CVE-2026-12224HIGHDokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST EndpointEPSS 0.2%CVE-2026-13110MEDIUMStoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX ActionEPSS 0.2%CVE-2023-52217MEDIUMWordPress WooCommerce Conversion Tracking plugin <= 2.0.11 - Broken Access Control vulnerabilityEPSS 0.2%