CVE-2026-18080
wedevs ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 1.17.8 via the save_attachments() function. This is due to missing file extension validation and missing path normalization when CRM Email Connect processes inbound IMAP email attachments. This makes it possible for unauthenticated attackers to send a crafted email to the site's configured inbound mailbox with a forged References header matching the plugin's expected pattern and an attachment filename such as `../helper....
- CVSS
- 9.8
- EPSS
- 0.67% 49.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.26