Input validation vulnerability in WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting 1.12.4

The WordPress ERP plugin is vulnerable to a type of attack called Reflected Cross-Site Scripting. This type of attack can occur when the plugin does not properly sanitize user input or escape output. If an attacker is able to get a user to click on a link or perform an action, they can inject malicious web scripts into pages, allowing them to take control of the user’s account. This vulnerability affects all versions up to and including 1.12.3 of the plugin.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.