Access violation vulnerability in WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting 1.10.5

The WP ERP Plugin for WordPress has a security vulnerability which could allow sensitive data to be exposed in versions up to, and including, 1.10.5. This vulnerability exists because of missing authorization checks in certain functions, such as the ‘generate_csv_url’ function. This function could leak a nonce, which is a code used to import CSV files.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.