CVE-2023-2744 Information

Description

The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the type parameter in the erp/v1/accounting/v1/people REST API endpoint before using it in a SQL statement leading to a SQL injection exploitable by high privilege users such as admin.

Reference

https://wpscan.com/vulnerability/435da8a1-9955-46d7-a508-b5738259e731

Share on: