The WordPress ERP plugin is vulnerable to a type of attack called Reflected Cross-Site Scripting. This type of attack can occur when the plugin does not properly sanitize user input or escape output. If an attacker is able to get a user to click on a link or perform an action, they can inject malicious web scripts into pages, allowing them to take control of the user’s account. This vulnerability affects all versions up to and including 1.12.3 of the plugin.