Vulnerability index

Browse CVEs

41 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Erp HIGH 7.5
CVE-2024-12812

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDO…

Fix: 1.13.4+
Fix from $1,950 2025-05-15
Wemail HIGH 7.5
CVE-2025-47540

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail wemail allows Retrieve Embedded Sensitive D…

Fix: 1.14.14+
Fix from $1,950 2025-05-07
Wp Project Manager MEDIUM 5.4
CVE-2025-2541

The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2…

Fix: 2.6.23+
Fix from $1,600 2025-04-11
Wp Project Manager MEDIUM 5.4
CVE-2025-3100

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stor…

Fix: 2.6.23+
Fix from $1,600 2025-04-09
Wp Project Manager HIGH 8.8
CVE-2025-32280

Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Request Forgery.This issue affe…

Fix: after 2.6.22
Fix from $1,950 2025-04-04
Wp Project Manager MEDIUM 6.5
CVE-2024-13500

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time…

Fix: 2.6.18+
Fix from $1,600 2025-02-15
Wp Project Manager MEDIUM 6.5
CVE-2024-13752

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unau…

Fix: 2.6.18+
Fix from $1,600 2025-02-15
Happy Addons For Elementor MEDIUM 5.4
CVE-2024-12852

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse C…

Fix: 3.15.2+
Fix from $1,600 2025-01-08
Wp Project Manager MEDIUM 6.5
CVE-2024-12195

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL …

Fix: 2.6.17+
Fix from $1,600 2025-01-04
Wp Project Manager MEDIUM 6.5
CVE-2024-10548

The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Proj…

Fix: 2.6.16+
Fix from $1,600 2024-12-19
Wp Project Manager CRITICAL 9.8
CVE-2023-40003

Missing Authorization vulnerability in weDevs WP Project Manager wedevs-project-manager allows Exploiting Incorrectly Configured Access Control Secur…

Fix: 2.6.8+
Fix from $2,300 2024-12-13
Wp Project Manager MEDIUM 5.3
CVE-2024-10520

The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' metho…

Fix: 2.6.15+
Fix from $1,600 2024-11-20
Wp Project Manager HIGH 7.3
CVE-2024-10174

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Inse…

Fix: 2.6.14+
Fix from $1,950 2024-11-13
Recaptcha Integration MEDIUM 6.1
CVE-2024-8739

The ReCaptcha Integration for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without …

Fix: 1.2.6+
Fix from $1,600 2024-11-02
Wp Erp MEDIUM 6.1
CVE-2024-47640

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP ERP erp allows Reflected XSS.This iss…

Fix: 1.13.3+
Fix from $1,600 2024-10-29
Wp User Frontend HIGH 7.2
CVE-2024-38693

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Frontend allows SQL Injection.Th…

Fix: 4.0.8+
Fix from $1,950 2024-08-29
Wemail MEDIUM 6.1
CVE-2024-43238

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows DOM-Based XSS.This …

Fix: 1.14.6+
Fix from $1,600 2024-08-18
Wp Erp HIGH 8.8
CVE-2024-6666

The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all versions up to, and including, 1.13.…

Fix: 1.13.1+
Fix from $1,950 2024-07-11
Happy Addons For Elementor MEDIUM 5.4
CVE-2024-5790

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute within the plugin's Gradient…

Fix: 3.11.2+
Fix from $1,600 2024-06-29
Wemail MEDIUM 5.3
CVE-2024-34822

Missing Authorization vulnerability in weDevs weMail.This issue affects weMail: from n/a through 1.14.2.

Fix: 1.14.3+
Fix from $1,600 2024-06-11
Woocommerce Conversion Tracking MEDIUM 6.3
CVE-2023-52217

Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.…

Fix: 2.0.12+
Fix from $1,600 2024-06-11
Wp Erp HIGH 7.2
CVE-2024-1173

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL…

Fix: 1.13.2+
Fix from $1,950 2024-05-02
Wp Erp HIGH 7.2
CVE-2024-0952

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL…

Fix: 1.13.0+
Fix from $1,950 2024-04-09
Wp Erp HIGH 7.2
CVE-2024-0913

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL…

Fix: after 1.12.9
Fix from $1,950 2024-03-29
Wp Erp MEDIUM 6.5
CVE-2024-0608

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to union-based SQ…

Fix: after 1.12.9
Fix from $1,600 2024-03-29
Wp Erp MEDIUM 6.1
CVE-2024-0609

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to Stored Cross-S…

Fix: after 1.12.9
Fix from $1,600 2024-03-29
Happy Addons For Elementor MEDIUM 6.1
CVE-2023-6632

The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1…

Fix: 2.10.0 / 3.10.0+
Fix from $1,600 2024-01-11
Happy Addons For Elementor MEDIUM 6.5
CVE-2023-51676

Server-Side Request Forgery (SSRF) vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through…

Fix: after 3.9.1.1
Fix from $1,600 2023-12-29
Wp Project Manager MEDIUM 5.4
CVE-2023-49860

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager – Task, team, and pro…

Fix: after 2.6.7
Fix from $1,600 2023-12-14
Wp Project Manager CRITICAL 9.8
CVE-2023-34383

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manage…

Fix: after 2.6.0
Fix from $2,300 2023-11-03