cleantalk
Vulnerabilities and Security Researches

WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting, 1edb46f67d9c7ebb9eb677bc7deae6d420b2cb16

Published on
Jul 26, 2022
Research Description
ERP: Complete HR, Accounting &amp; CRM Suite with WooCommerce CRM Support [erp] < 1.10.6 WP ERP <=1.10.5 - Sensitive Data Exposure The WP ERP Plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.10.5 due to missing authorization checks in a number of functions, including 'generate_csv_url', which leaks a nonce used to import CSV files.
Affected versions
max 1.10.6.
Status
vulnerable