PT-2026-82081 · WordPress · Erp: Complete Hr
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce versions prior to 1.17.9
Description
An unrestricted file type upload issue exists within the
save attachments() function. The flaw occurs when CRM Email Connect processes inbound IMAP email attachments due to a lack of file extension validation and path normalization. Unauthenticated attackers can send a crafted email to the configured inbound mailbox using a forged References header and a filename like ../helper.php. This allows the cron-based IMAP sync job to write attacker-controlled PHP files outside the protected crm-attachments directory and into wp-content/uploads/. If the server configuration allows PHP execution in the uploads directory, this can result in remote code execution. This issue requires the CRM module and IMAP Email Connect feature to be enabled and configured.Recommendations
Update to a version newer than 1.17.8.
As a temporary mitigation, disable the CRM module or the IMAP Email Connect feature.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Erp: Complete Hr