PatchSiren

wedevs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM wedevs CVE published 2026-08-25

CVE-2026-78470

The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can [truncated]

HIGH weDevs CVE published 2026-07-23

CVE-2026-65492

CVE-2026-65492 is a Cross-site Scripting vulnerability in weDevs Dokan Pro, affecting versions from n/a before 5.0.7. This issue allows Reflected XSS. The CVE record was published on 2026-07-23T12:18:42.430Z and has not been modified since then. The NVD entry is currently Deferred. Defenders should assess exposure and apply patches for Dokan Pro versions before 5.0.7, prioritizing verification of Dokan Pr [truncated]

MEDIUM wedevs CVE published 2026-07-17

CVE-2026-15349

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress has an authorization bypass vulnerability in all versions up to, and including, 1.17.6. Authenticated attackers with subscriber-level access and above can create arbitrary company locations in the ERP database. This vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. The vulnerability was reported by securi [truncated]

MEDIUM wedevs CVE published 2026-07-08

CVE-2026-5459

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.1 via the payment_page() function due to missing validation on the 'user_id' user controlled key. This makes it possible for unauthenticated attackers to activate a free subscription pack for [truncated]

MEDIUM wedevs CVE published 2026-07-03

CVE-2026-12731

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes in all versions up to, and including, 2.3.0. This vulnerability is caused by insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above [truncated]

HIGH weDevs CVE published 2026-06-26

CVE-2026-57322

A Cross-site Scripting (XSS) vulnerability exists in weMail, a WordPress plugin, from version n/a through 2.1.2. This issue allows for Reflected XSS attacks. The CVE record was published on 2026-06-26T15:16:48.860Z and was last modified on 2026-09-18T17:16:57.747Z. The NVD entry is currently Deferred. Defenders responsible for WordPress installations using the weMail plugin should assess exposure and prio [truncated]

HIGH wedevs CVE published 2026-06-25

CVE-2026-12077

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the 'latitude' and 'longitude' parameters in all versions up to, and including, 5.0.4. This vulnerability allows unauthenticated attackers to append additional SQL queries into existing queries, potentially leading to sensitive information disclosure. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severit [truncated]

MEDIUM weDevs CVE published 2026-06-11

CVE-2022-47150

A Cross-Site Request Forgery (CSRF) vulnerability exists in the weDevs WooCommerce Conversion Tracking plugin, affecting versions from n/a through 2.0.10. This issue allows for Cross-Site Request Forgery. The CVE record was published on 2026-06-11T12:16:29.607Z and has not been modified since then. The NVD entry is currently Deferred. Defenders should verify exposure, implement compensating controls, and [truncated]

MEDIUM wedevs CVE published 2026-06-09

CVE-2026-4058

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the user_subscription_cancel() function in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel any user [truncated]

HIGH weDevs CVE published 2026-05-22

CVE-2026-4834

CVE-2026-4834 describes an unauthenticated SQL injection in the WP ERP Pro plugin for WordPress affecting all versions up to and including 1.5.1. The issue is tied to insufficient escaping and insufficient query preparation for the user-supplied search_key parameter. Because the flaw can be reached without authentication and is associated with high confidentiality impact, it should be treated as a priorit [truncated]

MEDIUM weDevs CVE published 2026-04-08

CVE-2026-39520

A Missing Authorization vulnerability in the weDevs weDocs plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects weDocs: from n/a through <= 2.1.18. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of weDevs weDocs plugin, especially those with versions from n/a through <= 2.1.18, should be aware of this MEDIUM severity vuln [truncated]