Extension WordPress
Vulnérabilités WP Human Resource Management
Cette page rassemble les failles publiées pour WP Human Resource Management, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Human Resource Management
4 fiches
WP Human Resource Management 2.0.0 – 2.2.17 – Missing Authorization to Authenticated (Employee+) Privilege Escalation via wp_ajax_hrm_insert_employee AJAX Action
The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee() and update_empoyee() functions in versions 2.0.0 through 2.2.17. The AJAX handler reads the client-supplied $_POST['role'] and, after basic…
2.0.0-2.2.17
Non indiqué
03/07/2025
WP Human Resource Management 2.0.0 – 2.2.17 – Missing Authorization to Authenticated (Employee+) Arbitrary User Deletion via ajax_delete_employee Function
The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authorization within the ajax_delete_employee() function in versions 2.0.0 through 2.2.17. The plugin’s deletion handler reads the client-supplied $_POST['delete'] array and…
2.0.0-2.2.17
Non indiqué
03/07/2025
WP Human Resource Management < 2.2.6 – Sensitive Information Disclosure
The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role. This allows any authenticated user to access sensitive user information,…
[*, 2.2.6)
2.2.6
17/03/2019
WP Human Resource Management Plugin < 2.2.6 – Authorization Bypass
The WP Human Resource Management plugin before 2.2.6 for WordPress mishandles leave applications.
[*, 2.2.6)
2.2.6
23/02/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.