wedevs
Web & CMS Pluginscommercial
Latest CVEs
The 15 most recently published vulnerabilities affecting wedevs.
- CVE-2026-95525WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerability6.5
- CVE-2026-95523WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability6.5
- CVE-2026-95524WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability5.3
- CVE-2026-81283WordPress WP User Frontend plugin <= 4.3.10 - PHP Object Injection vulnerability8.8
- CVE-2026-18080ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment9.8
- CVE-2026-78470WP Project Manager Pro <= 4.0.1 - Authenticated (Subscriber+) SQL Injection6.5
- CVE-2026-78262WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerability9.8
- CVE-2026-73393WordPress Subscribe2 plugin <= 10.46 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-66466WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin <= 2.1.1 - Broken Access Control vulnerability7.5
- CVE-2026-11421ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support <= 1.17.4 - Authenticated (Custom+) SQL Injection via 'erpadvancefilter' Parameter6.5
- CVE-2026-13110StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action5.3
- CVE-2026-15411StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action5.3
- CVE-2026-13440StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'message_popup' Parameter7.2
- CVE-2026-65492WordPress Dokan Pro plugin < 5.0.7 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-59522WordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerability6.5