« Volver al listado

Wedevs

Wedevs WP ERP: vulnerabilidades y CVE

Wedevs WP ERP tiene 23 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE23
Últimos 12 meses6
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-96346Alta (7.6)0.28%—30 sept 2026
Author SQL Injection in WP ERP <= 1.17.9 versions.
CVE-2026-96343Alta (7.2)0.37%—30 sept 2026
Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.
CVE-2026-59522Media (6.5)0.34%—23 jul 2026
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
CVE-2026-31917Alta (8.5)0.36%—13 mar 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a through <= 1.16.10.
CVE-2025-67546Media (6.5)0.25%—18 dic 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Retrieve Embedded Sensitive Data.This issue affects WP ERP: from n/a through <= 1.16.6.
CVE-2025-63008Media (5.3)0.30%—9 dic 2025
Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.16.7.
CVE-2024-12812Alta (7.5)0.52%—15 may 2025
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can manipulate parameters to access the data…
CVE-2024-12808Media (4.8)0.31%—15 may 2025
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users…
CVE-2025-30896Media (5.4)0.36%—27 mar 2025
Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.13.4.
CVE-2023-45765Media (4.3)0.31%—2 ene 2025
Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.12.6.
CVE-2024-47640Media (6.1)0.35%—29 oct 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP ERP erp allows Reflected XSS.This issue affects WP ERP: from n/a through <= 1.13.2.
CVE-2024-6666Alta (8.8)0.53%—11 jul 2024
The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all versions up to, and including, 1.13.0 due to insufficient escaping on the user supplied parameter and lack…
CVE-2024-1173Alta (7.2)0.78%—2 may 2024
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including,…
CVE-2024-0952Alta (7.2)0.90%—9 abr 2024
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including,…
CVE-2024-0956Media (4.9)0.54%—29 mar 2024
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter via the…
CVE-2024-0913Alta (7.2)0.61%—29 mar 2024
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the erp/v1/accounting/v1/transactions/sales REST API…
CVE-2024-0609Media (6.1)0.54%—29 mar 2024
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key' parameter in all versions up to, and…
CVE-2024-0608Media (6.5)0.54%—29 mar 2024
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to union-based SQL Injection via the 'email' parameter in all versions up to, and…
CVE-2024-21747Media (4.9)0.58%—8 ene 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting.This issue…
CVE-2023-34008Media (6.1)0.46%—30 ago 2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in weDevs WP ERP plugin <= 1.12.3 versions.
CVE-2020-36735Media (4.3)0.46%—1 jul 2023
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.3. This is due to…
CVE-2023-2744Alta (7.2)2.6%—27 jun 2023
The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection…
CVE-2023-2743Media (6.1)0.49%—27 jun 2023
The ERP WordPress plugin before 1.12.4 does not sanitise and escape the employee_name parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System3
  2. T1210 Exploitation of Remote Services3
  3. T1059.007 JavaScript1
  4. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Wedevs