Unrestricted File Upload Vulnerability in ERP: Complete HR, Accounting & CRM Suite
CVE-2026-18080

9.8CRITICAL

What is CVE-2026-18080?

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is susceptible to an unrestricted file type upload due to insufficient validation of file extensions and improper path normalization in its save_attachments() function. This vulnerability allows unauthenticated attackers to exploit the plugin by sending a specially crafted email to the configured inbound mailbox. If the email contains an attachment with a manipulated filename that aligns with the plugin's expected format, it can trigger a cron-based IMAP synchronization process, which may write malicious PHP files outside the secure crm-attachments directory. In setups where PHP execution is allowed in the wp-content/uploads/ directory, this flaw can lead to remote code execution, making it crucial for site administrators to ensure the CRM Email Connect feature is properly configured and secured.

Affected Version(s)

ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce 0 <= 1.17.8

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Talal Nasraddeen
.