📦 Wp Erp

by Wedevs

🔍 What is Wp Erp?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-12812

HIGH CVSS 7.5 May 15, 2025

This vulnerability in the WP ERP WordPress plugin allows employees to access terminated employees' data by manipulating parameters. It affects WordPress sites using WP ERP plugin versions before 1.13....

CVE-2024-47640

HIGH CVSS 7.1 Oct 29, 2024

This CVE describes a reflected cross-site scripting (XSS) vulnerability in the weDevs WP ERP WordPress plugin. Attackers can inject malicious scripts via crafted URLs that execute when victims visit t...

CVE-2024-6666

HIGH CVSS 8.8 Jul 11, 2024

This SQL injection vulnerability in the WP ERP WordPress plugin allows authenticated attackers with Accounting Manager privileges to inject malicious SQL queries via the 'vendor_id' parameter. This ca...

CVE-2024-1173

HIGH CVSS 7.2 May 2, 2024

This vulnerability allows authenticated attackers with accounting manager or admin access to perform time-based SQL injection attacks via the id parameter in the WP ERP plugin. Attackers can extract s...

CVE-2024-0952

HIGH CVSS 7.2 Apr 9, 2024

This vulnerability allows authenticated attackers with accounting manager or admin privileges in WordPress to perform time-based SQL injection attacks via the id parameter in the WP ERP plugin. Attack...

CVE-2024-0913

HIGH CVSS 7.2 Mar 29, 2024

This vulnerability allows authenticated attackers with accounting manager or admin privileges in the WP ERP plugin to perform time-based SQL injection attacks. By exploiting insufficient input validat...

CVE-2024-0608

HIGH CVSS 8.8 Mar 29, 2024

This CVE describes a union-based SQL injection vulnerability in the WP ERP plugin for WordPress. Authenticated attackers with subscriber-level access or higher can exploit the 'email' parameter to exe...

CVE-2024-21747

HIGH CVSS 7.6 Jan 8, 2024

This SQL injection vulnerability in the WP ERP WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It affects all WordPress sites running WP ERP version 1.12.8 or earl...

CVE-2023-34008

HIGH CVSS 7.1 Aug 30, 2023

Unauthenticated reflected cross-site scripting (XSS) vulnerability in the weDevs WP ERP WordPress plugin allows attackers to inject malicious scripts into web pages viewed by users. This affects WordP...

CVE-2023-2744

HIGH CVSS 7.2 Jun 27, 2023

This CVE describes a SQL injection vulnerability in the ERP WordPress plugin affecting versions before 1.12.4. The vulnerability allows authenticated users with administrative privileges to execute ar...

CVE-2024-12808

MEDIUM CVSS 4.8 May 15, 2025

This vulnerability in the WP ERP WordPress plugin allows high-privilege users (like administrators) to inject malicious scripts into plugin settings, which then execute when other users view those set...