Extension WordPress
Vulnérabilités Employee, Leave and Recruitment Management System – Crew HRM
Cette page rassemble les failles publiées pour Employee, Leave and Recruitment Management System – Crew HRM, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Employee, Leave and Recruitment Management System – Crew HRM
3 fiches
Employee, Leave and Recruitment Management System <= 1.2.2 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Job Deletion via crewhrm_singleJobAction AJAX Action
The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly verifying that a user…
*-1.2.2
1.2.3
08/07/2026
Employee, Leave and Recruitment Management System – Crew HRM <= 1.2.2 – Missing Authorization
The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.2. This makes it possible…
*-1.2.2
1.2.3
02/06/2026
Crew HRM <= 1.1.1 – Unauthenticated PHP Object Injection
The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.1 via deserialization of untrusted input. This makes it possible for unauthenticated…
*-1.1.1
1.1.2
12/08/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.