Impact
The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress suffers from a SQL Injection flaw enabled by the 'erpadvancefilter' parameter. An attacker who can authenticate as a CRM Agent, CRM Manager or WordPress administrator can craft inputs that are not properly escaped and are directly interpolated into a quoted SQL WHERE clause. This leads to the execution of arbitrary SQL that can read sensitive database content, such as personal records. The weakness is a classic example of CWE‑89, where user supplied data is injected into an SQL statement without adequate sanitisation.
Affected Systems
Affected systems are WordPress sites running the ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin version 1.17.4 or earlier, including all releases up to and including 1.17.4. The vulnerability is present in all WordPress‑driven deployments of this plugin that grant CRM Agent or higher roles with the erp_crm_list_contact capability. The plugin identifier is wedevs:ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce.
Risk and Exploitability
The CVSS score for this flaw is 6.5, reflecting a moderate severity. Because the exploitation requires valid credentials and specific capabilities, the likelihood of a successful attack in the wild is limited, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. Defenders should consider that an authenticated attacker could conduct data theft or pivot to wider system compromise if credentials are compromised. Prompt remediation reduces the risk of undetected data exfiltration.
OpenCVE Enrichment