QID 730972
Date Published: 2023-11-21
QID 730972: WordPress Plugin WP ERP SQL Injection Vulnerability
WP ERP is the first full-fledged ERP (Enterprise Resource Planning) system through which you can simultaneously manage your WordPress site and business from a single platform.
CVE-2023-2744: WordPress plugin WP ERP does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
Affected Versions:
WordPress WP ERP Plugin versions prior to 1.12.4
QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for WP ERP Plugin using Blind Elephant Fingerprint technique.
Successful exploitation of this vulnerability may allow high privileged attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- WP ERP Plugin Release Notes -
wordpress.org/plugins/erp/#developers
CVEs related to QID 730972
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WP ERP Plugin Release Notes |
|