Impact
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin does not properly verify that a user is authorized to modify company data, allowing any authenticated user with subscriber-level access or higher to create arbitrary company locations. This vulnerability leads to unauthorized data creation that compromises the integrity of business information stored in the plugin.
Affected Systems
WordPress sites running the ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce from wedevs in version 1.17.6 or earlier are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need to be authenticated and possess subscriber or higher privileges to trigger the wp_ajax_erp-company-location handler, so the attack surface is limited to accounts that already have login access. Due to the missing authorization check, a legitimate logged‑in user can directly create company locations through the plugin's Ajax endpoint.
OpenCVE Enrichment