CVE-2026-18080 is an unauthenticated unrestricted file-upload vulnerability affecting ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce through version 1.17.8. The CRM Email Connect IMAP attachment-processing workflow invokes save_attachments() without adequate attachment extension validation or path normalization. A crafted inbound message can use a forged References header and a traversal-based attachment name to escape the protected attachment storage location and write attacker-controlled PHP into a web-accessible uploads location.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This four-file repository consists of an MIT license, documentation, and two exploit implementations: `exploit.py` is the primary automation entry point, while `exploit.php` is a standalone WP-CLI `wp eval-file` proof of concept. Both instantiate `WeDevs\ERP\CRM\GmailSync` and call `save_attachments()` with attacker-controlled attachment names such as `../../plugins/cve-2026-18080.php`. This tests the claimed lack of attachment filename normalization in WP ERP <=1.17.7, allowing writes to escape `wp-content/uploads/crm-attachments/` into plugin, theme, or uploads directories. The primary resulting capability is arbitrary PHP file upload followed by RCE through a POST-command webshell; a phpinfo-only probe is optional. The Python implementation is operational but environment-specific: it writes temporary code into a hard-coded local WordPress project, executes it via DDEV WP-CLI, checks the resulting local file, and only then performs HTTP requests to the target URL. Consequently, it demonstrates the vulnerable sink with local privileged execution rather than implementing the README's claimed unauthenticated IMAP-email delivery vector.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated arbitrary-file upload and path-traversal vulnerability in the WordPress ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin's CRM Email Connect IMAP attachment handler. A crafted email with a forged References header can cause PHP to be written outside the protected crm-attachments directory; where PHP execution is enabled in uploads, this may result in remote code execution.
A critical unauthenticated arbitrary file-upload and path-traversal vulnerability in the ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce WordPress plugin through version 1.17.8. Missing extension validation and path normalization in CRM Email Connect IMAP attachment processing can allow a crafted inbound email to place attacker-controlled PHP in the uploads directory, potentially resulting in remote code execution where PHP execution is enabled there.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.