CVE-2024-12812: Wedevs Wp ERP

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can manipulate parameters to access the data of terminated employees.

Affected products

  • Wedevs Wp ERP: before 1.13.4 (fixed in 1.13.4)

Published 2025-05-15. Last modified 2026-06-17.