The WP ERP plugin for WordPress, which helps with human resources, recruitment, job listings, and managing customer relationships and accounting through WooCommerce, has a security issue. This issue, called Stored Cross-Site Scripting, allows hackers with admin-level access to add harmful code to pages that can run whenever a user views them. This only affects certain types of installations.