The WP ERP plugin for WordPress, which helps businesses with human resources, recruitment, job listings, customer relationship management, and accounting, has a security vulnerability in all versions up to and including 1.12.9. This vulnerability allows attackers with certain privileges to add their own malicious code to existing queries, potentially accessing sensitive information from the database.