Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

weDevs — Vulnerabilities & Security Advisories 102

Browse all 102 CVE security advisories affecting weDevs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

weDevs operates as a prominent WordPress plugin developer, primarily serving the e-commerce and educational sectors through products like WooCommerce and LearnPress. With seventy-seven Common Vulnerabilities and Exposures (CVEs) currently on record, the company’s software has historically been susceptible to critical security flaws, most notably Remote Code Execution (RCE) and Cross-Site Scripting (XSS). These vulnerabilities frequently stemmed from insufficient input validation and improper access controls, allowing attackers to escalate privileges or execute arbitrary code on affected sites. While specific major incidents involving widespread data breaches are not extensively documented in public threat intelligence feeds, the high volume of CVEs indicates persistent challenges in securing codebases against injection attacks. This pattern underscores the risks associated with complex WordPress ecosystems, where plugin vulnerabilities often serve as primary entry points for site compromise, necessitating rigorous security audits and timely patch management for users relying on these tools.

CVE ID Title CVSS Severity Published
CVE-2026-73393 WordPress Subscribe2 plugin <= 10.46 - Cross Site Scripting (XSS) vulnerability — Subscribe2 CWE-79 7.1 High 2026-08-18
CVE-2026-66466 WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin <= 2.1.1 - Broken Access Control vulnerability — StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart CWE-862 7.5 High 2026-08-13
CVE-2026-11421 ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support <= 1.17.4 - Authenticated (Custom+) SQL Injection via 'erpadvancefilter' Parameter — ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce CWE-89 6.5 Medium 2026-08-05
CVE-2026-13110 StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action — StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce CWE-862 5.3 Medium 2026-07-28
CVE-2026-15411 StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action — StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce CWE-862 5.3 Medium 2026-07-28
CVE-2026-13440 StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'message_popup' Parameter — StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce CWE-79 7.2 High 2026-07-28
CVE-2026-59522 WordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerability — WP ERP CWE-862 6.5 Medium 2026-07-23
CVE-2026-15349 ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX Handler — ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce CWE-862 4.3 Medium 2026-07-17
CVE-2026-12418 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' Parameter — User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration CWE-639 5.3 Medium 2026-07-09
CVE-2026-13011 ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support <= 1.17.5 - Authenticated (HR Manager+) SQL Injection via 'orderby' Parameter — ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce CWE-89 6.5 Medium 2026-07-09
CVE-2026-12406 User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter — User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration CWE-862 5.3 Medium 2026-07-09
CVE-2026-5459 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Subscription Overwrite — User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration CWE-639 5.3 Medium 2026-07-08
CVE-2026-12731 weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes — weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot CWE-79 6.4 Medium 2026-07-03
CVE-2026-12729 weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX Action — weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot CWE-862 4.3 Medium 2026-07-03
CVE-2026-12734 weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block Attribute — weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot CWE-79 6.4 Medium 2026-07-03
CVE-2026-12224 Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint — Dokan Pro CWE-269 8.8 High 2026-07-01
CVE-2026-57334 WordPress WP User Frontend plugin <= 4.3.7 - Broken Access Control vulnerability — WP User Frontend CWE-862 6.5 Medium 2026-06-29
CVE-2026-57322 WordPress weMail plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulnerability — weMail CWE-79 7.1 High 2026-06-26
CVE-2026-12077 Dokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longitude' Parameters — Dokan Pro CWE-89 7.5 High 2026-06-25
CVE-2026-12079 Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter — Dokan Pro CWE-89 6.5 Medium 2026-06-25
CVE-2022-47150 WordPress WooCommerce Conversion Tracking plugin <= 2.0.10 - Cross-Site Request Forgery (CSRF) vulnerability — WooCommerce Conversion Tracking CWE-352 4.3 Medium 2026-06-11
CVE-2026-4058 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 - Missing Authorization to Authenticated (Subscriber+) Subscription Pack Cancellation — User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration CWE-862 4.3 Medium 2026-06-09
CVE-2026-4834 WP ERP Pro <= 1.5.1 - Unauthenticated SQL Injection via 'search_key' Parameter — WP ERP Pro CWE-89 7.5 High 2026-05-22
CVE-2026-5127 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Authenticated (Subscriber+) PHP Object Injection — User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration CWE-502 8.8 High 2026-05-08
CVE-2026-25468 WordPress Happy Addons for Elementor plugin <= 3.20.8 - Sensitive Data Exposure vulnerability — Happy Addons for Elementor CWE-497 5.3 Medium 2026-05-07
CVE-2026-42412 WordPress WP User Frontend plugin <= 4.3.1 - Broken Access Control vulnerability — WP User Frontend CWE-862 6.5 Medium 2026-04-29
CVE-2026-39520 WordPress weDocs plugin <= 2.1.18 - Broken Access Control vulnerability — weDocs CWE-862 5.3 Medium 2026-04-08
CVE-2026-32485 WordPress WP User Frontend plugin <= 4.2.8 - Broken Access Control vulnerability — WP User Frontend CWE-862 7.5 High 2026-03-25
CVE-2026-24364 WordPress WP User Frontend plugin <= 4.2.5 - Broken Access Control vulnerability — WP User Frontend CWE-862 6.5 Medium 2026-03-25
CVE-2026-2233 User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter — User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration CWE-862 5.3 Medium 2026-03-15

This page lists every published CVE security advisory associated with weDevs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.