The WP ERP Plugin for WordPress has a security vulnerability which could allow sensitive data to be exposed in versions up to, and including, 1.10.5. This vulnerability exists because of missing authorization checks in certain functions, such as the ‘generate_csv_url’ function. This function could leak a nonce, which is a code used to import CSV files.