What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a through <= 1.16.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a through <= 1.16.10.
Explanation of Vulnerability in Simple Terms
WP ERP versions up to 1.16.10 contain a SQL injection vulnerability in database query handling. An attacker with low-level user access can inject malicious SQL code to read sensitive data from the database, including user information and business records. The vulnerability affects the entire site scope and may also cause service disruption.
What an attacker can do
Read sensitive data from the database, including user credentials and business records.
Potential impact on your site
Confidential employee and business data can be extracted; site availability may be degraded.
Conditions required to exploit
Attacker must have a low-privilege user account (e.g., employee or subscriber role) on the site.
Key dates
External resources
Related vulnerabilities