SecAlerts
w

wedevs

Security Risk Profile

40
/100
medium

Security Risk Score

Comprehensive risk assessment based on 76 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 17, 2021 to present

76
Total CVEs
32
Critical+High
0
Exploited
17
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
17
Critical/High
Risk Level
40/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
4
High
28
Medium
44
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
11

Age Distribution

Common Weaknesses (CWE)

1
XSS
20
2
SQL Injection
18
3
CSRF
6
4
Infoleak
3
5
Input Validation
2

Most Affected Products

1. weDevs Wp Erp Wordpress16
2. weDevs Wp Project Manager Wordpress16
3. weDevs Happy Addons For Elementor Wordpress10
4. weDevs WP User Frontend8
5. WooCommerce WP ERP6

Recent Vulnerabilities

See more →
CVE-2026-95525
CVSS 6.5medium

WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerability

Sep 23, 2026🔧 No Patch
CVE-2026-57322
CVSS 7.1high

WordPress weMail plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulnerability

Jun 26, 2026🔧 No Patch
CVE-2026-12077
CVSS 7.5high

Dokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longitude' Parameters

Jun 25, 2026🔧 No Patch
CVE-2026-12079
CVSS 6.5medium

Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter

Jun 25, 2026🔧 No Patch
CVE-2026-10023
CVSS 4.3medium

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers

Jun 18, 2026🔧 No Patch
CVE-2026-22335
CVSS 8.5high

WordPress WooCommerce Frontend Manager – Ultimate plugin < 6.7.7 - SQL Injection vulnerability

Jun 17, 2026🔧 No Patch
CVE-2026-8089
CVSS 7.1high

weMail < 2.1.3 - Reflected Cross-Site Scripting

Jun 17, 2026🔧 No Patch
CVE-2022-47150
CVSS 4.3medium

WordPress WooCommerce Conversion Tracking plugin <= 2.0.10 - Cross-Site Request Forgery (CSRF) vulnerability

Jun 11, 2026🔧 No Patch
CVE-2026-5127
CVSS 8.8high

User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Authenticated (Subscriber+) PHP Object Injection

May 8, 2026🔧 No Patch
CVE-2026-25468
CVSS 5.3medium

WordPress Happy Addons for Elementor plugin <= 3.20.8 - Sensitive Data Exposure vulnerability

May 7, 2026

Monitor wedevs in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.