CVE-2026-18080

ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 1.17.8 via the save_attachments() function. This is due to missing file extension validation and missing path normalization when CRM Email Connect processes inbound IMAP email attachments. This makes it possible for unauthenticated attackers to send a crafted email to the site's configured inbound mailbox with a forged References header matching the plugin's expected pattern and an attachment filename such as `../helper.php`, causing the cron-based IMAP sync job to write attacker-controlled PHP outside of the .htaccess-protected `crm-attachments` directory and into `wp-content/uploads/`. On configurations where PHP executes in uploads, this can lead to remote code execution. Exploitation requires the CRM module and IMAP Email Connect feature to be enabled and configured.


We have discovered 480 live websites that are affected by CVE-2026-18080.

Run a Free Instant Scan




Affected Software

Product  Erp
Category Wordpress Plugins
Vulnerable Domains480 live websites (100% of Erp install base)
Vulnerable Versions
  • from 0 through 1.17.8
Vulnerable Versions Count52 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Aug 26, 2026
  • Updated - Aug 26, 2026

Credits

  • Talal Nasraddeen (finder)

Website Distribution by Country

Number of websites using CVE-2026-18080
United States136 websites



Germany38 websites
France30 websites
Spain22 websites
GB21 websites
Russia18 websites
India16 websites
Brazil15 websites
Italy13 websites
Netherlands13 websites

Website Distribution by TLD

Number of websites using CVE-2026-18080
.com237 websites
.org21 websites
.de19 websites
.ru13 websites
.fr12 websites
.com.br12 websites
.es11 websites
.nl10 websites
.it10 websites
.net8 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18080

Top websites that are affected by CVE-2026-18080. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States***,***
*****.org France***,***
**********.com Russia***,***
*************************************.org Austria*,***,***
**************.com Argentina*,***,***
***********.com United States*,***,***
*******.com United States*,***,***
***************.**.uk GB*,***,***
***************.org United States*,***,***
*****.dz Algeria*,***,***
See full domain list

FAQ

CVE-2026-18080 is Unrestricted Upload of File with Dangerous Type in Erp
A total of 480 websites have been identified as vulnerable to CVE-2026-18080, based on global website indexing conducted by WebTechSurvey.
The Erp is affected by the CVE-2026-18080 vulnerability.
Erp versions up to and including 1.17.8 are vulnerable to CVE-2026-18080.