PT-2026-82081 · WordPress · Erp: Complete Hr

·

CVE-2026-18080

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce versions prior to 1.17.9
Description An unrestricted file type upload issue exists within the save attachments() function. The flaw occurs when CRM Email Connect processes inbound IMAP email attachments due to a lack of file extension validation and path normalization. Unauthenticated attackers can send a crafted email to the configured inbound mailbox using a forged References header and a filename like ../helper.php. This allows the cron-based IMAP sync job to write attacker-controlled PHP files outside the protected crm-attachments directory and into wp-content/uploads/. If the server configuration allows PHP execution in the uploads directory, this can result in remote code execution. This issue requires the CRM module and IMAP Email Connect feature to be enabled and configured.
Recommendations Update to a version newer than 1.17.8. As a temporary mitigation, disable the CRM module or the IMAP Email Connect feature.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18080

Affected Products

Erp: Complete Hr