Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a through <= 1.16.10.
History

Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Wedevs
Wedevs wp Erp
Wordpress
Wordpress wordpress
Vendors & Products Wedevs
Wedevs wp Erp
Wordpress
Wordpress wordpress

Fri, 13 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a through <= 1.16.10.
Title WordPress WP ERP plugin <= 1.16.10 - SQL Injection vulnerability
Weaknesses CWE-89
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2026-03-13T11:41:53.941Z

Updated: 2026-03-13T15:21:10.021Z

Reserved: 2026-03-10T10:59:45.899Z

Link: CVE-2026-31917

cve-icon Vulnrichment

Updated: 2026-03-13T15:19:50.882Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-13T19:54:38.807

Modified: 2026-03-16T14:54:11.293

Link: CVE-2026-31917

cve-icon Redhat

No data.