First published: Mon Jan 08 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting.This issue affects WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting: from n/a through 1.12.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
weDevs WP ERP | <1.12.9 |
Update to 1.12.9 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21747 is classified as a high severity vulnerability due to the potential for SQL injection attacks.
To remediate CVE-2024-21747, upgrade the WP ERP plugin to version 1.12.9 or later.
CVE-2024-21747 affects all versions of WP ERP prior to version 1.12.9.
CVE-2024-21747 is an SQL Injection vulnerability caused by improper neutralization of special elements in SQL commands.
Websites utilizing weDevs WP ERP versions earlier than 1.12.9 are impacted by CVE-2024-21747.