Segurium Research Advisories erp

CVE-2026-18080: WP ERP before 1.17.8

critical 9.8 Arbitrary file upload

The CRM's IMAP connector saved mail attachments without checking the extension or normalising the path, so a crafted email could drop a PHP file into wp-content/uploads. CVE-2026-18080, CVSS 9.8, fixed in 1.17.8.

Plugin
WP ERP erp
Affected versions
before 1.17.8
Fixed in
1.17.8
Class
Arbitrary file upload
Severity
critical CVSS 9.8
CVE
CVE-2026-18080
Installs
5,000 active
Patch released
Sources
Read the teardown What the release changed, how the bug worked, and what to check on a site that ran the affected version.

Segurium Research writes these up from public source after the fix has shipped. We do not scan or probe third-party sites, and no teardown here carries a working exploit. Segurium itself is a WordPress malware scanner on the official directory at wordpress.org/plugins/segurium/.