Stored Cross-Site Scripting Issue in WP ERP by WordPress
CVE-2024-12808
What is CVE-2024-12808?
The WP ERP plugin, an integrated complete HR solution for WordPress, is vulnerable due to improper sanitization and escaping of certain settings. This flaw allows users with elevated privileges, such as administrators, to execute Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed in configurations like multisite setups. This vulnerability could lead to unauthorized script execution and potentially compromise the security of the affected WordPress site.
Affected Version(s)
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting 0 < 1.13.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved