Junglewise Threat Intelligence

CVE-2026-13011: weDevs WP ERP SQL injection in orderby parameter

CVE-2026-13011 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Vendors: weDevs.

Executive brief

The WP ERP plugin for WordPress, which manages human resources, accounting, and customer relationships, is vulnerable to a security flaw that allows certain authorized users to access sensitive database information. An attacker with HR Manager-level access or higher can manipulate database queries to extract data they are not supposed to see. This could lead to the exposure of confidential employee records, financial data, or customer information.

Technical details

A SQL injection vulnerability exists in the WP ERP plugin for WordPress due to insufficient escaping and lack of preparation on the 'orderby' parameter within SQL queries. This flaw is present in all versions up to and including 1.17.5. The vulnerability is exploitable by authenticated attackers with the 'erp_list_employee' capability, typically assigned to HR Manager-level users and above. By appending malicious SQL commands to existing queries, an attacker can perform unauthorized data extraction from the site's database. The issue was addressed in subsequent updates following version 1.17.5.

Affected products

  • weDevs ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce (WP ERP) 0 - 1.17.5

Timeline

  • 2026-07-09: advisory: NVD publication date
  • 2026-07-09: disclosed: Wordfence advisory published

References

Related threats