CVE-2025-67546: medium-severity vulnerability in weDevs WP ERP
WordPress WP ERP plugin <= 1.16.6 - Sensitive Data Exposure vulnerability
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.3%
exploitation probability
0.3%top 85% of all CVEs
observed exploitation
nono source reports it
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Retrieve Embedded Sensitive Data.This issue affects WP ERP: from n/a through <= 1.16.6.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
weDevs · WP ERPRelated CVEs — weDevs WP ERP
In the same product, most dangerous first.
CVE-2023-34008HIGHWordPress WP ERP Plugin <= 1.12.3 is vulnerable to Cross Site Scripting (XSS)EPSS 0.5%CVE-2024-47640HIGHWordPress WP ERP plugin <= 1.13.2 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2026-96343HIGHWordPress WP ERP plugin <= 1.17.9 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-30896MEDIUMWordPress WP ERP plugin <= 1.13.4 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-31917HIGHWordPress WP ERP plugin <= 1.16.10 - SQL Injection vulnerabilityEPSS 0.4%CVE-2026-59522MEDIUMWordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerabilityEPSS 0.3%