Description
WordPress Plugin WP Human Resource Management is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin WP Human Resource Management version 2.2.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.15 or latest
References
Related Vulnerabilities
WordPress Plugin weForms-Easy Drag & Drop Contact Form Builder For WordPress CSV Injection (1.6.3)
Atlassian Jira Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-39127)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-3557)
WordPress Plugin Store Locator Plus for WordPress SQL Injection (3.8.6)