top of page
perceptive_background_267k.jpg

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, an…

Published:

26 August 2026 at 00:00:00

Alert date:

26 August 2026 at 19:06:19

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities

CVE-2026-18080 affects the ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce WordPress plugin in all versions up to and including 1.17.8. The vulnerability exists in the save_attachments() function, which lacks file extension validation and path normalization when processing inbound IMAP email attachments via the CRM Email Connect feature. Unauthenticated attackers can send a crafted email with a forged References header and a path-traversal attachment filename (e.g., '../helper.php') to the site's configured inbound mailbox. The cron-based IMAP sync job then writes attacker-controlled PHP files outside the protected 'crm-attachments' directory into 'wp-content/uploads/'. On servers where PHP execution is permitted in the uploads directory, this can result in remote code execution. Exploitation requires the CRM module and IMAP Email Connect feature to be enabled and configured. A patch is available via the plugin's changeset 3656848.

Technical details

Mitigation steps:

Affected products:

ERP: Complete HR
Accounting & CRM Suite Built for WooCommerce
WordPress

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page