Impact
The vulnerability is a missing authorization flaw that allows an attacker to bypass access controls in the WordPress HR Management Lite plugin. Because the plugin fails to enforce proper permission checks, an unauthenticated or low‑privileged user could gain unauthorized access to sensitive human‑resources data such as employee records and salary information. The weakness is identified as CWE‑862, which means the application does not enforce required authorizations for the requested actions.
Affected Systems
The issue affects the WordPress HR Management Lite plugin developed by Weblizar, from any unsupported version up to and including version 3.6.0. Users running any of those releases on a WordPress site are exposed until they upgrade beyond the stated cut‑off.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, but the EPSS score of less than 1% shows that the probability of a real‑world exploit is very low. The vulnerability is not listed in the CISA KEV catalog, meaning there is no known active exploitation. Still, the flaw allows compromise of confidentiality and potential integrity of HR data if an attacker can reach the relevant administrative pages, typically via a compromised or low‑privilege user account, or by exploiting the plugin’s insufficiently protected endpoints.
OpenCVE Enrichment