Extension WordPress

Vulnérabilités ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

Cette page rassemble les failles publiées pour ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

24Vulnérabilités
0Critiques
24Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

24 fiches

CVE-2026-15349 Moyenne · 4,3
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX Handler

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.17.6. This is due to the plugin not properly verifying that a…

Versions affectées

*-1.17.6

Correctif

1.17.7

Publication

16/07/2026

CVE-2026-59522 Moyenne · 4,3
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.5 – Missing Authorization

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.17.5. This makes it…

Versions affectées

*-1.17.5

Correctif

1.17.6

Publication

15/07/2026

CVE-2026-13011 Moyenne · 6,5
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support <= 1.17.5 – Authenticated (HR Manager+) SQL Injection via 'orderby' Parameter

The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 1.17.5 due to insufficient…

Versions affectées

*-1.17.5

Correctif

1.17.6

Publication

08/07/2026

CVE-2024-12812 Moyenne · 4,3
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

WP ERP <= 1.13.3 – Authenticated (Employee+) Insecure Direct Object Reference

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.13.3 via the profile…

Versions affectées

*-1.13.3

Correctif

1.13.4

Publication

03/03/2025

CVE-2024-47640 Moyenne · 6,1
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

WP ERP <= 1.13.2 – Reflected Cross-Site Scripting

The WP ERP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.13.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-1.13.2

Correctif

1.13.3

Publication

21/10/2024

CVE-2024-6666 Élevée · 8,8
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

WP ERP <= 1.13.0 – Authenticated (Accounting Manager+) SQL Injection via vendor_id

The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all versions up to, and including, 1.13.0 due to insufficient escaping on the user supplied parameter and lack of sufficient…

Versions affectées

*-1.13.0

Correctif

1.13.1

Publication

10/07/2024

CVE-2024-1173 Élevée · 7,2
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 – Authenticated (AccountingManager+) SQL Injection

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.13.1…

Versions affectées

*-1.13.1

Correctif

1.13.2

Publication

01/05/2024

CVE-2024-0956 Moyenne · 4,9
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

WP ERP <= 1.13.0 – Authenticated (AccountingManager+) SQL Injection

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter via the erp/v1/accounting/v1/vendors/1/products/ REST route in all versions…

Versions affectées

*-1.13.0

Correctif

1.13.1

Publication

28/03/2024

CVE-2024-0609 Élevée · 7,2
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 – Unauthenticated Stored Cross-Site Scripting

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key' parameter in all versions up to, and including, 1.13.1…

Versions affectées

*-1.13.1

Correctif

1.13.2

Publication

28/03/2024

CVE-2024-0608 Moyenne · 6,5
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 – Authenticated (Subscriber+) SQL Injection

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to union-based SQL Injection via the 'email' parameter in all versions up to, and including, 1.13.1…

Versions affectées

*-1.13.1

Correctif

1.13.2

Publication

28/03/2024

CVE-2024-0913 Élevée · 7,2
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

WP ERP <= 1.13.0 – Authenticated (Accounting Manager+) SQL Injection

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the erp/v1/accounting/v1/transactions/sales REST API endpoint in all versions up to, and…

Versions affectées

*-1.13.0

Correctif

1.13.1

Publication

28/03/2024

CVE-2023-45765 Informationnelle
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

WP ERP <= 1.12.6 – Missing Authorization via admin notice dismissal

The WP ERP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple admin notice dismissal function in versions up to, and including, 1.12.6. This makes it possible for authenticated…

Versions affectées

*-1.12.6

Correctif

1.12.7

Publication

12/10/2023

CVE-2023-2743 Moyenne · 6,1
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce

WP ERP <= 1.12.3 – Reflected Cross-Site Scripting

The WP ERP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'employee_name' parameter in versions up to, and including, 1.12.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

[*, 1.12.4)

Correctif

1.12.4

Publication

05/06/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités