Impact
The Crew HRM plugin for WordPress fails to verify that an authenticated user has permission to delete, archive, unarchive, or duplicate job listings. An attacker with subscriber or higher level can supply any job identifier to the crewhrm_singleJobAction AJAX endpoint. The plugin transmits the required nonce through a front‑end localization script, allowing such users to obtain it easily and bypass the check. The result is loss and alteration of job data, associated stages, addresses, and applications, which can disrupt recruitment workflows and compromise data integrity.
Affected Systems
WordPress sites running the Crew HRM Employee, Leave and Recruitment Management System plugin, version 1.2.2 or earlier releases.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack requires only an authenticated WordPress session with no additional privileges or remote code execution are needed. Once the attacker obtains the nonce, the deletion can be performed through a simple AJAX POST, making the exploitation straightforward for insiders or compromised accounts.
OpenCVE Enrichment