


Perceptive Security
SOC/SIEM Consultancy

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, an…
Published:
26 August 2026 at 00:00:00
Alert date:
26 August 2026 at 19:06:19
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities
CVE-2026-18080 affects the ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce WordPress plugin in all versions up to and including 1.17.8. The vulnerability exists in the save_attachments() function, which lacks file extension validation and path normalization when processing inbound IMAP email attachments via the CRM Email Connect feature. Unauthenticated attackers can send a crafted email with a forged References header and a path-traversal attachment filename (e.g., '../helper.php') to the site's configured inbound mailbox. The cron-based IMAP sync job then writes attacker-controlled PHP files outside the protected 'crm-attachments' directory into 'wp-content/uploads/'. On servers where PHP execution is permitted in the uploads directory, this can result in remote code execution. Exploitation requires the CRM module and IMAP Email Connect feature to be enabled and configured. A patch is available via the plugin's changeset 3656848.
Technical details
Mitigation steps:
Affected products:
ERP: Complete HR
Accounting & CRM Suite Built for WooCommerce
WordPress
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18080
https://plugins.trac.wordpress.org/changeset/3656848/erp
https://www.wordfence.com/threat-intel/vulnerabilities/id/b9d11eb9-5e18-459f-a9d4-cccb1d593402?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
