The WP ERP plugin for WordPress, which includes features for human resources, recruitment, job listings, customer relationship management (CRM), and accounting, has a security vulnerability. This vulnerability allows attackers who are logged in with at least subscriber-level access to manipulate the email parameter and add their own SQL queries to the existing database queries. This could potentially expose sensitive information from the database.