Executive brief
WP ERP is a business management plugin for WordPress used to handle human resources, customer relations, and accounting. A security flaw allows users with basic 'Subscriber' accounts to bypass security checks and access sensitive information they should not be able to see. This could lead to the exposure of private business data or employee records to unauthorized individuals.
Technical details
A broken access control vulnerability exists in the WP ERP plugin for WordPress due to missing authorization checks (CWE-862). An attacker authenticated with a low-privileged 'Subscriber' role can exploit this flaw over the network to access sensitive information that should be restricted to higher-privileged users. The vulnerability is present in versions up to and including 1.17.5. The issue was addressed in version 1.17.6 by implementing proper authorization checks.
Affected products
- weDevs WP ERP <= 1.17.5
Timeline
- 2026-07-02: other: Reported by K. Sorrachat
- 2026-07-15: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD