Description
WordPress Plugin WP Human Resource Management is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin WP Human Resource Management version 2.2.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.15 or latest
References
Related Vulnerabilities
Caddy Web Server Improper Authentication Vulnerability (CVE-2018-21246)
Apache Tomcat URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-11784)
WordPress Plugin WPE Indoshipping Multiple Remote File Inclusion Vulnerabilities (2.5.0)
WordPress Cleartext Storage of Sensitive Information Vulnerability (CVE-2017-14990)