Unrated severityNVD Advisory· Published May 15, 2025· Updated Aug 27, 2025
WP ERP < 1.13.4 - Custom+ Unauthorized Access to Terminated Employee Information
CVE-2024-12812
Description
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can manipulate parameters to access the data of terminated employees.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/757e76fd-830f-4d1c-8b89-dfad7c9c1f37/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.