Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

weDevs — Vulnerabilities & Security Advisories 102

Browse all 102 CVE security advisories affecting weDevs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

weDevs operates as a prominent WordPress plugin developer, primarily serving the e-commerce and educational sectors through products like WooCommerce and LearnPress. With seventy-seven Common Vulnerabilities and Exposures (CVEs) currently on record, the company’s software has historically been susceptible to critical security flaws, most notably Remote Code Execution (RCE) and Cross-Site Scripting (XSS). These vulnerabilities frequently stemmed from insufficient input validation and improper access controls, allowing attackers to escalate privileges or execute arbitrary code on affected sites. While specific major incidents involving widespread data breaches are not extensively documented in public threat intelligence feeds, the high volume of CVEs indicates persistent challenges in securing codebases against injection attacks. This pattern underscores the risks associated with complex WordPress ecosystems, where plugin vulnerabilities often serve as primary entry points for site compromise, necessitating rigorous security audits and timely patch management for users relying on these tools.

CVE ID Title CVSS Severity Published
CVE-2023-34382 WordPress Dokan Plugin <= 3.7.19 is vulnerable to PHP Object Injection — Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy CWE-502 4.4 Medium 2023-12-19
CVE-2023-49860 WordPress WP Project Manager Plugin <= 2.6.7 is vulnerable to Cross Site Scripting (XSS) — WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts CWE-79 6.5 Medium 2023-12-14
CVE-2023-34383 WordPress WP Project Manager Plugin <= 2.6.0 is vulnerable to SQL Injection — WP Project Manager CWE-89 8.5 High 2023-11-03
CVE-2023-3636 WP Project Manager <= 2.6.4 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation — Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker CWE-269 8.8 High 2023-08-31
CVE-2023-34008 WordPress WP ERP Plugin <= 1.12.3 is vulnerable to Cross Site Scripting (XSS) — WP ERP CWE-79 7.1 High 2023-08-30
CVE-2023-28989 WordPress Happy Addons for Elementor Plugin <= 3.8.2 is vulnerable to Cross Site Request Forgery (CSRF) — Happy Addons for Elementor CWE-352 4.3 Medium 2023-07-10
CVE-2020-36745 WP Project Manager <= 2.4.0 - Cross-Site Request Forgery Bypass — Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker CWE-352 4.3 Medium 2023-07-01
CVE-2020-36735 WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.6.3 - Cross-Site Request Forgery Bypass — ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support CWE-352 4.3 Medium 2023-07-01
CVE-2023-3407 Subscribe2 <= 10.40 - Cross-Site Request Forgery — Subscribe2 – Form, Email Subscribers & Newsletters CWE-352 4.3 Medium 2023-06-28
CVE-2023-1844 Subscribe2 <= 10.40 - Missing Authorization — Subscribe2 – Form, Email Subscribers & Newsletters CWE-862 4.3 Medium 2023-06-28
CVE-2021-36826 WordPress WP Project Manager plugin <= 2.4.13 - Stored Cross-Site Scripting (XSS) vulnerability — WP Project Manager (WordPress plugin) CWE-79 5.4 Medium 2022-04-04
CVE-2021-24292 Happy Addons for Elementor Free < 2.24.0 and Pro < 1.17.0 - Contributor+ Stored XSS — Happy Addons for Elementor CWE-79 5.4 - 2021-05-17

This page lists every published CVE security advisory associated with weDevs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.