Vulnerabilities > Wedevs > High

DATE CVE VULNERABILITY TITLE RISK
2024-08-29 CVE-2024-38693 SQL Injection vulnerability in Wedevs WP User Frontend
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.This issue affects WP User Frontend: from n/a through 4.0.7.
network
low complexity
wedevs CWE-89
7.2
2024-07-11 CVE-2024-6666 SQL Injection vulnerability in Wedevs WP ERP
The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ parameter in all versions up to, and including, 1.13.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
wedevs CWE-89
8.8
2023-12-20 CVE-2023-26525 SQL Injection vulnerability in Wedevs Dokan
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from n/a through 3.7.12.
network
low complexity
wedevs CWE-89
8.1
2023-12-19 CVE-2023-34382 Deserialization of Untrusted Data vulnerability in Wedevs Dokan
Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from n/a through 3.7.19.
network
low complexity
wedevs CWE-502
8.8
2023-08-31 CVE-2023-3636 Unspecified vulnerability in Wedevs WP Project Manager
The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function.
network
low complexity
wedevs
8.8
2023-07-10 CVE-2023-28989 Cross-Site Request Forgery (CSRF) vulnerability in Wedevs Happy Addons for Elementor
Cross-Site Request Forgery (CSRF) vulnerability in weDevs Happy Addons for Elementor plugin <= 3.8.2 versions.
network
low complexity
wedevs CWE-352
8.8
2023-07-01 CVE-2020-36745 Unspecified vulnerability in Wedevs WP Project Manager
The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0.
network
low complexity
wedevs
8.8
2023-06-27 CVE-2023-2744 Unspecified vulnerability in Wedevs WP ERP
The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
network
low complexity
wedevs
7.2