CVE-2026-18080 | wedevs ERP Complete HR, Accounting & CRM Suite Plugin up to 1.17.8 on WordPress CRM Email Connect helper.php save_attachments unrestricted upload
A vulnerability described as critical has been identified in wedevs ERP Complete HR, Accounting & CRM Suite Plugin up to 1.17.8 on WordPress. The affected element is the function save_attachments of the file helper.php of the component CRM Email Connect. Executing a manipulation can lead to unrestricted upload.
The identification of this vulnerability is CVE-2026-18080. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More