The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can manipulate parameters to access the data of terminated employees.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-15292 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can manipulate parameters to access the data of terminated employees.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 22 Aug 2025 14:30:00 +0000

Type Values Removed Values Added
Description The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 has an issue where employees can manipulate parameters to access the data of terminated employees. The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can manipulate parameters to access the data of terminated employees.

Tue, 10 Jun 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Wedevs
Wedevs wp Erp
Weaknesses CWE-862
CPEs cpe:2.3:a:wedevs:wp_erp:*:*:*:*:free:wordpress:*:*
Vendors & Products Wedevs
Wedevs wp Erp

Tue, 20 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 has an issue where employees can manipulate parameters to access the data of terminated employees.
Title WP ERP < 1.13.4 - Custom+ Unauthorized Access to Terminated Employee Information
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-08-27T12:00:29.663Z

Reserved: 2024-12-19T19:04:46.667Z

Link: CVE-2024-12812

cve-icon Vulnrichment

Updated: 2025-05-19T20:31:50.478Z

cve-icon NVD

Status : Modified

Published: 2025-05-15T20:15:37.747

Modified: 2025-08-22T15:15:30.900

Link: CVE-2024-12812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.