Author SQL Injection in WP ERP <= 1.17.9 versions.
CVE-2026-96346 at the National Vulnerability Database