OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-96343

HIGH · CVSS 7.2 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects the WP ERP plugin versions up to 1.17.9, allowing for PHP Object Injection through custom roles. This could lead to remote code execution, enabling attackers to manipulate the application and potentially compromise the underlying server. Organizations using this plugin should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-96343
Severity
HIGH
CVSS
7.2
EPSS
0.37%

Original NVD Description

Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.