Skip to main content

Vendor/product archive

wedevs / wp_erp CVEs

Beta · best-effort

16 CVEs tagged to wedevs / wp_erp0 Critical, 10 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-12812

Published May 15, 2025

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can ma…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12808

Published May 15, 2025

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and escape some of its settings,…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45765

Published Jan 2, 2025

Missing Authorization vulnerability in weDevs WP ERP erp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP ERP: from n/a through <= 1.1…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-47640

Published Oct 29, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP ERP erp allows Reflected XSS.This issue affects WP ERP: from n/a th…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6666

Published Jul 11, 2024

The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all versions up to, and including, 1.13.0 due to insufficient escaping…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1173

Published May 2, 2024

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id paramete…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0952

Published Apr 9, 2024

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id paramete…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0956

Published Mar 29, 2024

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id paramete…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0913

Published Mar 29, 2024

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the erp/v1/acco…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0609

Published Mar 29, 2024

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0608

Published Mar 29, 2024

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to union-based SQL Injection via the 'email' pa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21747

Published Jan 8, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP | Complete HR solution with recruitment & job listings | WooCom…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-34008

Published Aug 30, 2023

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in weDevs WP ERP plugin <= 1.12.3 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-36735

Published Jul 1, 2023

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2744

Published Jun 27, 2023

The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL s…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2743

Published Jun 27, 2023

The ERP WordPress plugin before 1.12.4 does not sanitise and escape the employee_name parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1