A popular WordPress plugin called “WP ERP” has a security vulnerability that allows hackers to access sensitive information from the database. This is due to a lack of proper protection and preparation in the software’s code. If you have this plugin installed, it is important to update it to the latest version to fix this issue.