weDevs 厂商相关 113 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。
weDevs 是一家专注于 WordPress 生态的开发商,核心产品涵盖 WooCommerce 插件及教育管理系统。其软件历史上频繁出现远程代码执行、跨站脚本及越权访问等高危漏洞,累计收录 77 条 CVE。安全团队需重点关注其插件更新机制,因部分漏洞源于输入验证缺失。建议用户及时升级至最新稳定版,并严格遵循最小权限原则部署,以降低潜在攻击面。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-47682 | WordPress plugin WP User Frontend 安全漏洞 — WP User Frontend CWE-269 | 7.2 | High | 2024-05-17 |
| CVE-2024-1173 | WordPress plugin WP ERP 安全漏洞 — ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support CWE-89 | 7.2 | High | 2024-05-02 |
| CVE-2024-0952 | WordPress Plugin WP ERP 安全漏洞 — ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support CWE-89 | 7.2 | High | 2024-04-09 |
| CVE-2024-0956 | WordPress Plugin WP ERP 安全漏洞 — ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support CWE-89 | 4.9 | Medium | 2024-03-29 |
| CVE-2024-0609 | WordPress Plugin WP ERP 安全漏洞 — ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support CWE-79 | 7.2 | High | 2024-03-29 |
| CVE-2024-0608 | WordPress Plugin WP ERP 安全漏洞 — ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support CWE-89 | 6.5 | Medium | 2024-03-29 |
| CVE-2024-0913 | WordPress Plugin WP ERP 安全漏洞 — ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support CWE-89 | 7.2 | High | 2024-03-29 |
| CVE-2024-24711 | WordPress Plugin WooCommerce Conversion Tracking 安全漏洞 — WooCommerce Conversion Tracking CWE-862 | 4.3 | Medium | 2024-03-26 |
| CVE-2023-6632 | WordPress Plugin Happy Addons for Elementor 安全漏洞 — Happy Addons for Elementor Pro CWE-79 | 6.1 | Medium | 2024-01-11 |
| CVE-2024-21747 | WordPress Plugin WP ERP SQL注入漏洞 — WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting CWE-89 | 7.6 | High | 2024-01-08 |
| CVE-2023-26525 | WordPress Plugin Dokan SQL注入漏洞 — Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy CWE-89 | 7.1 | High | 2023-12-20 |
| CVE-2023-34382 | WordPress plugin Dokan 代码问题漏洞 — Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy CWE-502 | 4.4 | Medium | 2023-12-19 |
| CVE-2023-49860 | WordPress Plugin WP Project Manager 跨站脚本漏洞 — WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts CWE-79 | 6.5 | Medium | 2023-12-14 |
| CVE-2023-34383 | WordPress Plugin WP Project Manager SQL注入漏洞 — WP Project Manager CWE-89 | 8.5 | High | 2023-11-03 |
| CVE-2023-3636 | WordPress Plugin WP Project Manager 权限许可和访问控制问题漏洞 — Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker CWE-269 | 8.8 | High | 2023-08-31 |
| CVE-2023-34008 | WordPress plugin WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting 跨站脚本漏洞 — WP ERP CWE-79 | 7.1 | High | 2023-08-30 |
| CVE-2023-28989 | Wrodpress Plugin Happy Addons for Elementor 跨站请求伪造漏洞 — Happy Addons for Elementor CWE-352 | 4.3 | Medium | 2023-07-10 |
| CVE-2020-36745 | WordPress Plugin WP Project Manager 跨站请求伪造漏洞 — Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker CWE-352 | 4.3 | Medium | 2023-07-01 |
| CVE-2020-36735 | WordPress Plugin WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting 跨站请求伪造漏洞 — ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support CWE-352 | 4.3 | Medium | 2023-07-01 |
| CVE-2023-3407 | WordPress Plugin Subscribe2 跨站请求伪造漏洞 — Subscribe2 – Form, Email Subscribers & Newsletters CWE-352 | 4.3 | Medium | 2023-06-28 |
| CVE-2023-1844 | WordPress Plugin Subscribe2 安全漏洞 — Subscribe2 – Form, Email Subscribers & Newsletters CWE-862 | 4.3 | Medium | 2023-06-28 |
| CVE-2021-36826 | WordPress plugin weDevs WP Project Manager 跨站脚本漏洞 — WP Project Manager (WordPress plugin) CWE-79 | 5.4 | Medium | 2022-04-04 |
| CVE-2021-24292 | WordPress plugin 跨站脚本漏洞 — Happy Addons for Elementor CWE-79 | 5.4 | - | 2021-05-17 |
本页汇总了 weDevs 厂商截至目前公开的全部 113 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。