The WordPress ERP plugin is vulnerable to a security issue known as SQL Injection in versions up to 1.12.4. This issue is caused by the plugin not properly protecting input from users with administrator-level access or above. Because of this, these users can add extra SQL queries to existing ones, potentially allowing them to access sensitive information stored in the database.