Unrestricted File Upload Vulnerability in ERP: Complete HR, Accounting & CRM Suite
CVE-2026-18080
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 August 2026
What is CVE-2026-18080?
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is susceptible to an unrestricted file type upload due to insufficient validation of file extensions and improper path normalization in its save_attachments() function. This vulnerability allows unauthenticated attackers to exploit the plugin by sending a specially crafted email to the configured inbound mailbox. If the email contains an attachment with a manipulated filename that aligns with the plugin's expected format, it can trigger a cron-based IMAP synchronization process, which may write malicious PHP files outside the secure crm-attachments directory. In setups where PHP execution is allowed in the wp-content/uploads/ directory, this flaw can lead to remote code execution, making it crucial for site administrators to ensure the CRM Email Connect feature is properly configured and secured.
Affected Version(s)
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce 0 <= 1.17.8