CVE-2024-47640
- EPSS 0.35%
- Veröffentlicht 29.10.2024 14:15:06
- Zuletzt bearbeitet 23.04.2026 15:19:24
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP ERP erp allows Reflected XSS.This issue affects WP ERP: from n/a through <= 1.13.2.
CVE-2024-6666
- EPSS 0.54%
- Veröffentlicht 11.07.2024 07:15:07
- Zuletzt bearbeitet 08.04.2026 19:22:13
The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all versions up to, and including, 1.13.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...
CVE-2024-1173
- EPSS 0.78%
- Veröffentlicht 02.05.2024 17:15:10
- Zuletzt bearbeitet 08.04.2026 18:20:29
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.13.1 due to insufficient esca...
CVE-2024-0952
- EPSS 0.91%
- Veröffentlicht 09.04.2024 19:15:15
- Zuletzt bearbeitet 08.04.2026 19:19:19
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.12.9 due to insufficient esca...
CVE-2024-0956
- EPSS 0.55%
- Veröffentlicht 29.03.2024 07:15:42
- Zuletzt bearbeitet 08.04.2026 19:19:19
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter via the erp/v1/accounting/v1/vendors/1/products/ REST route in all ve...
CVE-2024-0913
- EPSS 0.62%
- Veröffentlicht 29.03.2024 07:15:42
- Zuletzt bearbeitet 08.04.2026 18:19:00
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the erp/v1/accounting/v1/transactions/sales REST API endpoint in all versions up to, a...
CVE-2024-0609
- EPSS 0.54%
- Veröffentlicht 29.03.2024 07:15:41
- Zuletzt bearbeitet 08.04.2026 18:18:53
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key' parameter in all versions up to, and including, 1.13.1 due to insuffi...
CVE-2024-0608
- EPSS 0.55%
- Veröffentlicht 29.03.2024 07:15:41
- Zuletzt bearbeitet 08.04.2026 18:18:53
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to union-based SQL Injection via the 'email' parameter in all versions up to, and including, 1.13.1 due to insufficien...
CVE-2024-21747
- EPSS 0.58%
- Veröffentlicht 08.01.2024 17:15:08
- Zuletzt bearbeitet 28.04.2026 19:23:09
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting.This issue affects WP ERP | Complete HR solution...
CVE-2023-34008
- EPSS 0.45%
- Veröffentlicht 30.08.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:06:23
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in weDevs WP ERP plugin <= 1.12.3 versions.