A popular WordPress plugin called WP ERP, which is used for managing human resources, recruitment, job listings, customer relationship management, and accounting, has a security vulnerability. This vulnerability allows attackers with certain levels of access to manipulate the plugin’s database by adding their own malicious code. This could potentially expose sensitive information.