Vulnerabilities > Wedevs > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-11-03 CVE-2023-34383 SQL Injection vulnerability in Wedevs WP Project Manager
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a through 2.6.0.
network
low complexity
wedevs CWE-89
critical
9.8
2022-12-12 CVE-2022-3915 Unspecified vulnerability in Wedevs Dokan
The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
network
low complexity
wedevs
critical
9.8
2022-11-21 CVE-2021-24649 Unspecified vulnerability in Wedevs WP User Frontend
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption().
network
low complexity
wedevs
critical
9.8