CVE-2026-96346
- EPSS 0.28%
- Veröffentlicht 30.09.2026 12:27:22
- Zuletzt bearbeitet 30.09.2026 14:18:08
Author SQL Injection in WP ERP <= 1.17.9 versions.
CVE-2026-96343
- EPSS 0.37%
- Veröffentlicht 30.09.2026 12:27:18
- Zuletzt bearbeitet 30.09.2026 14:18:07
Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.
CVE-2026-59522
- EPSS 0.32%
- Veröffentlicht 23.07.2026 11:18:16
- Zuletzt bearbeitet 23.07.2026 16:17:29
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
CVE-2026-31917
- EPSS 0.31%
- Veröffentlicht 13.03.2026 11:41:53
- Zuletzt bearbeitet 22.04.2026 21:30:26
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a through <= 1.16.10.
CVE-2025-67546
- EPSS 0.25%
- Veröffentlicht 18.12.2025 07:22:19
- Zuletzt bearbeitet 15.04.2026 00:35:42
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Retrieve Embedded Sensitive Data.This issue affects WP ERP: from n/a through <= 1.16.6.
CVE-2025-63008
- EPSS 0.31%
- Veröffentlicht 09.12.2025 14:52:27
- Zuletzt bearbeitet 07.10.2026 20:10:01
Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.16.7.
CVE-2024-12812
- EPSS 0.52%
- Veröffentlicht 15.05.2025 20:15:37
- Zuletzt bearbeitet 22.08.2025 15:15:30
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can manipulate parameters to access the data of terminated employees.
CVE-2024-12808
- EPSS 0.31%
- Veröffentlicht 15.05.2025 20:15:37
- Zuletzt bearbeitet 10.06.2025 12:29:25
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored ...
CVE-2025-30896
- EPSS 0.34%
- Veröffentlicht 27.03.2025 10:55:47
- Zuletzt bearbeitet 23.04.2026 15:27:17
Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.13.4.
CVE-2023-45765
- EPSS 0.31%
- Veröffentlicht 02.01.2025 12:15:09
- Zuletzt bearbeitet 29.04.2026 10:16:18
Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.12.6.