CyberRota Analysis
AI-GeneratedThe vulnerability affects the WP ERP plugin versions up to 1.17.9, allowing for PHP Object Injection through custom roles. This could lead to remote code execution, enabling attackers to manipulate the application and potentially compromise the underlying server. Organizations using this plugin should prioritize patching to mitigate the risk of exploitation.
CVE
CVE-2026-96343
Severity
HIGH
CVSS
7.2
EPSS
0.37%
Original NVD Description
Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.