Wp Erp
21 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Wp Erp, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Wp Erp CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 2 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 2 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 1 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High13
- Medium8
Latest CVEs
The 15 most recently published vulnerabilities affecting Wp Erp.
- CVE-2026-59522WordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerability6.5
- CVE-2026-31917WordPress WP ERP plugin <= 1.16.10 - SQL Injection vulnerability8.5
- CVE-2025-67546WordPress WP ERP plugin <= 1.16.6 - Sensitive Data Exposure vulnerability6.5
- CVE-2025-63008WordPress WP ERP plugin <= 1.16.7 - Broken Access Control vulnerability5.3
- CVE-2024-12808WP ERP | Complete HR solution with recruitment < 1.13.4 - Admin+ Stored XSS4.8
- CVE-2024-12812WP ERP < 1.13.4 - Custom+ Unauthorized Access to Terminated Employee Information7.5
- CVE-2025-30896WordPress WP ERP plugin <= 1.13.4 - Broken Access Control vulnerability5.4
- CVE-2023-45765WordPress WP ERP plugin <= 1.12.6 - Broken Access Control vulnerability4.3
- CVE-2024-47640WordPress WP ERP plugin <= 1.13.2 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2024-6666WP ERP <= 1.13.0 - Authenticated (Accounting Manager+) SQL Injection via vendor_id8.8
- CVE-2024-1173WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Authenticated (AccountingManager+) SQL Injection7.2
- CVE-2024-0952WP ERP <= 1.12.9 - Authenticated (Accounting Manager+) SQL Injection via id7.2
- CVE-2024-0956WP ERP <= 1.13.0 - Authenticated (AccountingManager+) SQL Injection7.2
- CVE-2024-0608WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Authenticated (Subscriber+) SQL Injection8.8
- CVE-2024-0609WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Unauthenticated Stored Cross-Site Scripting7.2
Product grouping is registry-driven, with AI assist and human review. How it works