What is CVE-2026-11421?
CVE-2026-11421 is an SQL Injection vulnerability in the ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress via the 'erpadvancefilter' parameter. It affects all versions up to and including 1.17.4 due to insufficient escaping and preparation of user-supplied data. Updating to the latest patched version is recommended.
Azərbaycanca: CVE-2026-11421 WordPress üçün ERP: Complete HR, Accounting & CRM Suite pluginində 'erpadvancefilter' parametri vasitəsilə SQL Injection zəifliyidir. Bu, 1.17.4 və daha əvvəlki versiyalara təsir edir və istifadəçi tərəfindən təqdim olunan məlumatların düzgün işlənməməsi səbəbindən yaranır. Pluginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which WordPress plugin is affected by CVE-2026-11421?
CVE-2026-11421 is an SQL Injection vulnerability affecting the ERP: Complete HR, Accounting & CRM Suite plugin for WordPress.
Which versions of the plugin are vulnerable?
The vulnerability affects all versions up to and including 1.17.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.