Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18080— ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment

Quick assessment

Affected
wedevs ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

适用于 WordPress 的 ERP:完整 HR、会计及 CRM 套件(WooCommerce 插件)存在不受限制的文件类型上传漏洞。该漏洞影响 1.17.8 及之前所有版本,经由 函数触发。漏洞成因在于 CRM 邮件连接功能在处理传入的 IMAP 电子邮件附件时,缺少文件扩展名验证以及路径规范化措施。这使得未认证的攻击者能够向网站配置的收件邮箱发送构造好的邮件,使用与插件预期模式匹配的伪造 References 头部,并附带文件名如 的附件。从而使得基于 cron 的 IMAP 同步作业将攻击者控制的 PHP

CVSS 9.8 · Critical

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
wedevs ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce ≤ 1.17.8 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18080

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment
Source: CVE Program / CVE List V5
Vulnerability Description
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 1.17.8 via the save_attachments() function. This is due to missing file extension validation and missing path normalization when CRM Email Connect processes inbound IMAP email attachments. This makes it possible for unauthenticated attackers to send a crafted email to the site's configured inbound mailbox with a forged References header matching the plugin's expected pattern and an attachment filename such as `../helper.php`, causing the cron-based IMAP sync job to write attacker-controlled PHP outside of the .htaccess-protected `crm-attachments` directory and into `wp-content/uploads/`. On configurations where PHP executes in uploads, this can lead to remote code execution. Exploitation requires the CRM module and IMAP Email Connect feature to be enabled and configured.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wedevs ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce 0 ~ 1.17.8 -

II. Public POCs for CVE-2026-18080

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18080

登录查看更多情报信息。

Security Blog Posts for CVE-2026-18080 (1)

Vendor Pages for CVE-2026-18080 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-18080

No comments yet


Leave a comment