CVEs we hold for Wedevs
Records whose assigning authority named Wedevs as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-81283WordPress WP User Frontend plugin <= 4.3.10 - PHP Object Injection vulnerabilityweDevs WP User Frontend
CVE-2026-78470WP Project Manager Pro <= 4.0.1 - Authenticated (Subscriber+) SQL Injectionwedevs WP Project Manager Pro
CVE-2026-78262WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerabilityweDevs WP Project Manager
CVE-2026-73393WordPress Subscribe2 plugin <= 10.46 - Cross Site Scripting (XSS) vulnerabilityweDevs Subscribe2
CVE-2026-66466WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart…weDevs StoreGrowth: Smart Sales Booster for WooCommerce |…
CVE-2026-57334WordPress WP User Frontend plugin <= 4.3.7 - Broken Access Control vulnerabilityweDevs WP User Frontend
CVE-2026-57322WordPress weMail plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulnerabilityweDevs weMail
CVE-2026-5459User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 -…wedevs User Frontend: AI Powered Frontend Posting, User…
CVE-2026-5127User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 -…wedevs User Frontend: AI Powered Frontend Posting, User…
CVE-2026-4834WP ERP Pro <= 1.5.1 - Unauthenticated SQL Injection via 'search_key' ParameterweDevs WP ERP Pro
CVE-2026-42412WordPress WP User Frontend plugin <= 4.3.1 - Broken Access Control vulnerabilityweDevs WP User Frontend
CVE-2026-4058User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 - Missing…wedevs User Frontend: AI Powered Frontend Posting, User…
CVE-2026-32485WordPress WP User Frontend plugin <= 4.2.8 - Broken Access Control vulnerabilityweDevs WP User Frontend
CVE-2026-32478WordPress WP Project Manager Pro plugin <= 4.0.1 - SQL Injection vulnerabilityweDevs Pte. Ltd WP Project Manager Pro
CVE-2026-25468WordPress Happy Addons for Elementor plugin <= 3.20.8 - Sensitive Data Exposure vulnerabilityweDevs Happy Addons for Elementor
CVE-2026-24944WordPress Subscribe2 plugin <= 10.44 - Broken Access Control vulnerabilityweDevs Subscribe2
CVE-2026-24364WordPress WP User Frontend plugin <= 4.2.5 - Broken Access Control vulnerabilityweDevs WP User Frontend
CVE-2026-2233User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing…wedevs User Frontend: AI Powered Frontend Posting, User…
CVE-2026-18080ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via…wedevs ERP: Complete HR, Accounting & CRM Suite Built for…
CVE-2026-1565User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 -…wedevs User Frontend: AI Powered Frontend Posting, User…
CVE-2026-15411StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 -…wedevs StoreGrowth – Upsell, BOGO, Quick View, Direct…
CVE-2026-15349ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated…wedevs ERP: Complete HR, Accounting & CRM Suite Built for…
CVE-2026-13440StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 -…wedevs StoreGrowth – Upsell, BOGO, Quick View, Direct…
CVE-2026-13110StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 -…wedevs StoreGrowth – Upsell, BOGO, Quick View, Direct…
CVE-2026-13011ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support <= 1.17.5 - Authenticated (HR…wedevs ERP: Complete HR, Accounting & CRM Suite Built for…
CVE-2026-12734weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+)…wedevs weDocs: AI Powered Knowledge Base, Docs…
CVE-2026-12731weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+)…wedevs weDocs: AI Powered Knowledge Base, Docs…
CVE-2026-12729weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Missing Authorization to…wedevs weDocs: AI Powered Knowledge Base, Docs…
CVE-2026-12418User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 - Insecure…wedevs User Frontend: AI Powered Frontend Posting, User…
CVE-2026-12406User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id'…wedevs User Frontend: AI Powered Frontend Posting, User…
CVE-2026-12224Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpointwedevs Dokan Pro
CVE-2026-12079Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameterwedevs Dokan Pro
CVE-2026-12077Dokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longitude' Parameterswedevs Dokan Pro
CVE-2026-11421ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support <= 1.17.4 - Authenticated (Custom+) SQL Injection…wedevs ERP: Complete HR, Accounting & CRM Suite Built for…
CVE-2025-8994WP Project Manager <= 2.6.26 - Authenticated (Subscriber+) SQL Injection via 'completed_at_operator'wedevs Project Manager – AI Powered Project Management…
CVE-2025-68040WordPress WP Project Manager plugin <= 3.0.1 - Sensitive Data Exposure vulnerabilityweDevs WP Project Manager
CVE-2025-67546WordPress WP ERP plugin <= 1.16.6 - Sensitive Data Exposure vulnerabilityweDevs WP ERP
CVE-2025-58673WordPress WP User Frontend Plugin <= 4.1.12 - Content Injection VulnerabilityweDevs WP User Frontend
CVE-2025-58672WordPress WP User Frontend Plugin <= 4.1.12 - Broken Access Control VulnerabilityweDevs WP User Frontend
CVE-2025-58269WordPress WP Project Manager Plugin <= 2.6.25 - Sensitive Data Exposure VulnerabilityweDevs WP Project Manager
CVE-2025-47540WordPress weMail plugin <= 1.14.13 - Sensitive Data Exposure VulnerabilityweDevs weMail
CVE-2025-39377WordPress Appsero Helper plugin <= 1.3.4 - SQL Injection vulnerabilityweDevs Appsero Helper
CVE-2025-32280WordPress WP Project Manager plugin < 2.6.25 - Cross Site Request Forgery (CSRF) VulnerabilityweDevs WP Project Manager
CVE-2025-3100WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 -…wedevs Project Manager – AI Powered Project Management…
CVE-2025-3055WP User Frontend Pro <= 4.1.3 - Authenticated (Subscriber+) Arbitrary File Deletionwedevs WP User Frontend Pro
CVE-2025-3054WP User Frontend Pro <= 4.1.3 - Authenticated (Subscriber+) Arbitrary File Uploadwedevs WP User Frontend Pro
CVE-2025-2541WP Project Manager <= 2.6.22 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploadwedevs Project Manager – AI Powered Project Management…
CVE-2025-22649WordPress WP Project Manager plugin <= 2.6.22 - Cross Site Scripting (XSS) vulnerabilityweDevs WP Project Manager
CVE-2025-14574weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.1.15 - Unauthenticated Sensitive…wedevs weDocs: AI Powered Knowledge Base, Docs…
CVE-2025-14348weMail <= 2.0.7 - Insufficient Authorization via x-wemail-user Header to Sensitive Information Disclosurewedevs weMail: Email Marketing, Email Automation…
CVE-2025-14339weMail <= 2.0.7 - Missing Authorization to Unauthenticated Form Deletionwedevs weMail: Email Marketing, Email Automation…
CVE-2025-14047WP User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletionwedevs User Frontend: AI Powered Frontend Posting, User…
CVE-2025-13921weDocs <= 2.1.16 - Missing Authorization to Authenticated (Subscriber+) Documentation Post Updatewedevs weDocs: AI Powered Knowledge Base, Docs…
CVE-2025-12809dokan pro <= 4.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposurewedevs Dokan Pro
CVE-2025-12505weDocs <= 2.1.14 - Missing Authorization to Settings Updatewedevs weDocs: AI Powered Knowledge Base, Docs…
CVE-2024-8739ReCaptcha Integration for WordPress <= 1.2.5 - Reflected Cross-Site Scriptingwedevs ReCaptcha Integration for WordPress
CVE-2024-6666WP ERP <= 1.13.0 - Authenticated (Accounting Manager+) SQL Injection via vendor_idwedevs ERP: Complete HR, Accounting & CRM Suite with…
CVE-2024-47640WordPress WP ERP plugin <= 1.13.2 - Reflected Cross Site Scripting (XSS) vulnerabilityweDevs WP ERP
CVE-2024-43238WordPress weMail plugin <= 1.14.5 - Cross Site Scripting (XSS) vulnerabilityweDevs weMail
CVE-2024-38693WordPress WP User Frontend plugin <= 4.0.7 - SQL Injection vulnerabilityweDevs WP User Frontend
CVE-2024-37946WordPress ReCaptcha Integration for WordPress plugin <= 1.2.7 - Cross Site Scripting (XSS) vulnerabilityweDevs ReCaptcha Integration for WordPress
CVE-2024-24711WordPress WooCommerce Conversion Tracking plugin <= 2.0.11 - Broken Access Control vulnerabilityweDevs WooCommerce Conversion Tracking
CVE-2024-21747WordPress WP ERP Plugin <= 1.12.8 is vulnerable to SQL InjectionweDevs WP ERP | Complete HR solution with recruitment & job…
CVE-2024-13752WP Project Manager <= 2.6.17 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Updatewedevs Project Manager – AI Powered Project Management…
CVE-2024-13500WP Project Manager <= 2.6.17 - Authenticated (Subscriber+) SQL Injection via orderby Parameterwedevs Project Manager – AI Powered Project Management…
CVE-2024-13436Appsero Helper <= 1.3.2 - Cross-Site Request Forgery to Stored Cross-Site Scriptingwedevs Appsero Helper
CVE-2024-12195WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 -…wedevs Project Manager – AI Powered Project Management…
CVE-2024-1173WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Authenticated…wedevs ERP: Complete HR, Accounting & CRM Suite with…
CVE-2024-11582Subscribe2 – Form, Email Subscribers & Newsletters <= 10.43 - Unauthenticated Stored Cross-Site Scripting via IP…wedevs Subscribe2 – Form, Email Subscribers & Newsletters
CVE-2024-10548WP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST APIwedevs Project Manager – AI Powered Project Management…
CVE-2024-10520WP Project Manager <= 2.6.14 - Missing Authorization to Project Milestone and Task Creation/Deletionwedevs Project Manager – AI Powered Project Management…
CVE-2024-10174WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 -…wedevs Project Manager – AI Powered Project Management…
CVE-2024-0956WP ERP <= 1.13.0 - Authenticated (AccountingManager+) SQL Injectionwedevs ERP: Complete HR, Accounting & CRM Suite with…
CVE-2024-0952WP ERP <= 1.12.9 - Authenticated (Accounting Manager+) SQL Injection via idwedevs ERP: Complete HR, Accounting & CRM Suite with…
CVE-2024-0913WP ERP <= 1.13.0 - Authenticated (Accounting Manager+) SQL Injectionwedevs ERP: Complete HR, Accounting & CRM Suite with…
CVE-2024-0609WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 -…wedevs ERP: Complete HR, Accounting & CRM Suite with…
CVE-2024-0608WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Authenticated…wedevs ERP: Complete HR, Accounting & CRM Suite with…
CVE-2023-6632Happy Addons for Elementor <= 3.9.1.1 - Reflected Cross-Site ScriptingweDevs Happy Addons for Elementor Pro; thehappymonster…
CVE-2023-52217WordPress WooCommerce Conversion Tracking plugin <= 2.0.11 - Broken Access Control vulnerabilityweDevs WooCommerce Conversion Tracking
CVE-2023-49860WordPress WP Project Manager Plugin <= 2.6.7 is vulnerable to Cross Site Scripting (XSS)weDevs WP Project Manager – Task, team, and project…
CVE-2023-47682WordPress WP User Frontend plugin <= 3.6.5 - Authenticated Privilege Escalation vulnerabilityweDevs WP User Frontend
CVE-2023-45002WordPress WP User Frontend plugin <= 3.6.8 - Broken Access Control vulnerabilityweDevs WP User Frontend
CVE-2023-40003WordPress WP Project Manager plugin <= 2.6.7 - Broken Access Control vulnerabilityweDevs WP Project Manager
CVE-2023-3636WP Project Manager <= 2.6.4 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalationwedevs Project Manager – AI Powered Project Management…
CVE-2023-34383WordPress WP Project Manager Plugin <= 2.6.0 is vulnerable to SQL InjectionweDevs WP Project Manager
CVE-2023-34382WordPress Dokan Plugin <= 3.7.19 is vulnerable to PHP Object InjectionweDevs Dokan – Best WooCommerce Multivendor Marketplace…
CVE-2023-3407Subscribe2 <= 10.40 - Cross-Site Request Forgerywedevs Subscribe2 – Form, Email Subscribers & Newsletters
CVE-2023-34008WordPress WP ERP Plugin <= 1.12.3 is vulnerable to Cross Site Scripting (XSS)weDevs WP ERP
CVE-2023-28989WordPress Happy Addons for Elementor Plugin <= 3.8.2 is vulnerable to Cross Site Request Forgery (CSRF)weDevs Happy Addons for Elementor
CVE-2023-26525WordPress Dokan Plugin <= 3.7.12 is vulnerable to SQL InjectionweDevs Dokan – Best WooCommerce Multivendor Marketplace…
CVE-2023-1844Subscribe2 <= 10.40 - Missing Authorizationwedevs Subscribe2 – Form, Email Subscribers & Newsletters
CVE-2022-47150WordPress WooCommerce Conversion Tracking plugin <= 2.0.10 - Cross-Site Request Forgery (CSRF) vulnerabilityweDevs WooCommerce Conversion Tracking
CVE-2021-36826WordPress WP Project Manager plugin <= 2.4.13 - Stored Cross-Site Scripting (XSS) vulnerabilityweDevs WP Project Manager (WordPress plugin)
CVE-2021-24292Happy Addons for Elementor Free < 2.24.0 and Pro < 1.17.0 - Contributor+ Stored XSSweDevs Happy Addons Pro for Elementor
CVE-2020-36745WP Project Manager <= 2.4.0 - Cross-Site Request Forgery Bypasswedevs Project Manager – AI Powered Project Management…
CVE-2020-36735WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.6.3 - Cross-Site…wedevs ERP: Complete HR, Accounting & CRM Suite with…
107 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.