VendorsweDevswp_erpall versions
Vulnerabilities

weDevs WP ERP

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2024-6666
WP ERP <= 1.13.0 - Authenticated (Accounting Manager+) SQL Injection via vendor_id
Published 2024-07-11 · Modified
8.8EPSS 0.005
CVE-2024-21747
WordPress WP ERP Plugin <= 1.12.8 is vulnerable to SQL Injection
Published 2024-01-08 · Modified
7.6EPSS 0.006
CVE-2024-12812
WP ERP < 1.13.4 - Custom+ Unauthorized Access to Terminated Employee Information
Published 2025-05-15 · Modified
7.5EPSS 0.005
CVE-2023-2744
WP ERP < 1.12.4 - Admin+ SQL Injection
Published 2023-06-27 · Modified
7.2EPSS 0.026
CVE-2024-0952
WP ERP <= 1.12.9 - Authenticated (Accounting Manager+) SQL Injection via id
Published 2024-04-09 · Modified
7.2EPSS 0.009
CVE-2024-1173
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Authenticated (AccountingManager+) SQL Injection
Published 2024-05-02 · Modified
7.2EPSS 0.008
CVE-2024-0913
WP ERP <= 1.13.0 - Authenticated (Accounting Manager+) SQL Injection
Published 2024-03-29 · Modified
7.2EPSS 0.006
CVE-2024-0609
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Unauthenticated Stored Cross-Site Scripting
Published 2024-03-29 · Modified
7.2EPSS 0.005
CVE-2023-34008
WordPress WP ERP Plugin <= 1.12.3 is vulnerable to Cross Site Scripting (XSS)
Published 2023-08-30 · Modified
7.1EPSS 0.005
CVE-2024-47640
WordPress WP ERP plugin <= 1.13.2 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-10-29 · Modified
7.1EPSS 0.004
CVE-2024-0608
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Authenticated (Subscriber+) SQL Injection
Published 2024-03-29 · Modified
6.5EPSS 0.005
CVE-2023-2743
WP ERP < 1.12.4 - Reflected Cross-Site Scripting
Published 2023-06-27 · Modified
6.1EPSS 0.005
CVE-2024-0956
WP ERP <= 1.13.0 - Authenticated (AccountingManager+) SQL Injection
Published 2024-03-29 · Modified
4.9EPSS 0.005
CVE-2024-12808
WP ERP | Complete HR solution with recruitment < 1.13.4 - Admin+ Stored XSS
Published 2025-05-15 · Analyzed
4.8EPSS 0.003
CVE-2020-36735
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.6.3 - Cross-Site Request Forgery Bypass
Published 2023-07-01 · Modified
4.3EPSS 0.005
CVE-2023-45765
WordPress WP ERP plugin <= 1.12.6 - Broken Access Control vulnerability
Published 2025-01-02 · Modified
4.3EPSS 0.003