CVE-2024-21747: WordPress WP ERP Plugin <= 1.12.8 is vulnerable to SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting.This issue affects WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting: from n/a through 1.12.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
weDevs WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accountingto a version that resolves this vulnerability.Fixed in 1.12.9
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21747?
CVE-2024-21747 is classified as a high severity vulnerability due to the potential for SQL injection attacks.
How do I fix CVE-2024-21747?
To remediate CVE-2024-21747, upgrade the WP ERP plugin to version 1.12.9 or later.
Which software versions are affected by CVE-2024-21747?
CVE-2024-21747 affects all versions of WP ERP prior to version 1.12.9.
What type of vulnerability is CVE-2024-21747?
CVE-2024-21747 is an SQL Injection vulnerability caused by improper neutralization of special elements in SQL commands.
Who is impacted by CVE-2024-21747?
Websites utilizing weDevs WP ERP versions earlier than 1.12.9 are impacted by CVE-2024-21747.