WP ERP <=1.10.5 - Sensitive Data Exposure
2022-07-26 00:00
AnonymousStrategic Overview
StatusPatched in 1.10.6
Affected Version
<= 1.10.5CVSS6.3Medium
CVE
N/AVulnerability Overview
The WP ERP Plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.10.5 due to missing authorization checks in a number of functions, including 'generate_csv_url', which leaks a nonce used to import CSV files.
Technical Analysis
REMEDIATION: Update to version 1.10.6, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C