Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.
CVE-2026-96343 at the National Vulnerability Database