Junglewise Threat Intelligence

CVE-2026-4834: WP ERP WP ERP Pro SQL injection in search_key parameter

CVE-2026-4834 · Severity: high · CVSS 7.5 · Published 2026-05-22

Executive brief

WP ERP Pro, a business management plugin for WordPress used for HR, CRM, and accounting, contains a security flaw that allows unauthorized individuals to access sensitive database information. By sending specially crafted requests, an attacker can bypass security controls to view private company data, including employee records or financial details. This could lead to significant data exposure and regulatory compliance issues for businesses using the software.

Technical details

The WP ERP Pro plugin for WordPress is vulnerable to unauthenticated SQL Injection via the 'search_key' parameter in versions up to and including 1.5.1. The vulnerability stems from insufficient escaping of user-supplied input and a lack of proper preparation of the SQL query (improper neutralization of special elements). An attacker can exploit this by appending malicious SQL commands to existing queries, enabling the extraction of sensitive data from the site's database. The attack can be performed remotely without any authentication or user interaction. As of the advisory date, users are advised to check for updates beyond version 1.5.1.

Affected products

  • WP ERP WP ERP Pro up to, and including, 1.5.1

Timeline

  • 2026-05-22: disclosed: Initial disclosure by Wordfence and NVD publication

References