Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%

weDevs — Vulnerabilities & Security Advisories 76

Browse all 76 CVE security advisories affecting weDevs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPaused
CVE-2024-24711 WordPress WooCommerce Conversion Tracking plugin <= 2.0.11 - Broken Access Control vulnerability — WooCommerce Conversion TrackingCWE-862 4.3 Medium2024-03-26
CVE-2023-6632 Happy Addons for Elementor <= 3.9.1.1 - Reflected Cross-Site Scripting — Happy Addons for Elementor ProCWE-79 6.1 Medium2024-01-11
CVE-2024-21747 WordPress WP ERP Plugin <= 1.12.8 is vulnerable to SQL Injection — WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & AccountingCWE-89 7.6 High2024-01-08
CVE-2023-26525 WordPress Dokan Plugin <= 3.7.12 is vulnerable to SQL Injection — Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, EtsyCWE-89 7.1 High2023-12-20
CVE-2023-34382 WordPress Dokan Plugin <= 3.7.19 is vulnerable to PHP Object Injection — Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, EtsyCWE-502 4.4 Medium2023-12-19
CVE-2023-49860 WordPress WP Project Manager Plugin <= 2.6.7 is vulnerable to Cross Site Scripting (XSS) — WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt chartsCWE-79 6.5 Medium2023-12-14
CVE-2023-34383 WordPress WP Project Manager Plugin <= 2.6.0 is vulnerable to SQL Injection — WP Project ManagerCWE-89 8.8 -2023-11-03
CVE-2023-3636 WP Project Manager <= 2.6.4 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation — Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time TrackerCWE-269 8.8 High2023-08-31
CVE-2023-34008 WordPress WP ERP Plugin <= 1.12.3 is vulnerable to Cross Site Scripting (XSS) — WP ERPCWE-79 7.1 High2023-08-30
CVE-2023-28989 WordPress Happy Addons for Elementor Plugin <= 3.8.2 is vulnerable to Cross Site Request Forgery (CSRF) — Happy Addons for ElementorCWE-352 4.3 Medium2023-07-10
CVE-2020-36745 WP Project Manager <= 2.4.0 - Cross-Site Request Forgery Bypass — Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time TrackerCWE-352 4.3 Medium2023-07-01
CVE-2020-36735 WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.6.3 - Cross-Site Request Forgery Bypass — ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM SupportCWE-352 4.3 Medium2023-07-01
CVE-2023-1844 Subscribe2 <= 10.40 - Missing Authorization — Subscribe2 – Form, Email Subscribers & NewslettersCWE-862 4.3 Medium2023-06-28
CVE-2023-3407 Subscribe2 <= 10.40 - Cross-Site Request Forgery — Subscribe2 – Form, Email Subscribers & NewslettersCWE-352 4.3 Medium2023-06-28
CVE-2021-36826 WordPress WP Project Manager plugin <= 2.4.13 - Stored Cross-Site Scripting (XSS) vulnerability — WP Project Manager (WordPress plugin)CWE-79 5.4 Medium2022-04-04
CVE-2021-24292 Happy Addons for Elementor Free < 2.24.0 and Pro < 1.17.0 - Contributor+ Stored XSS — Happy Addons for ElementorCWE-79 5.4 -2021-05-17

This page lists every published CVE security advisory associated with weDevs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.