Impact
The Crew HRM plugin for WordPress contains a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels. This weakness, identified as CWE‑862, can enable an unauthorized user to access or manipulate data and functionality that should be restricted to privileged accounts, potentially exposing sensitive personnel information.
Affected Systems
The vulnerability affects Sekander Badsha’s Crew HRM WordPress plugin versions up to and including 1.2.2. Sites running any of these versions, regardless of other WordPress components, are at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. No EPSS score is available, suggesting limited evidence of active exploitation, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is via the web interface, where an attacker can bypass normal role checks. Attacking requires the plugin to be present but does not need additional privilege beyond the normal user context.
OpenCVE Enrichment