Executive brief
Crew HRM is a WordPress plugin used for managing human resources and employee data. A security flaw in the plugin's access control settings allows logged-in users with low-level permissions, such as subscribers, to perform actions they should not be authorized to do. This could lead to unauthorized changes to HR data or disruption of the management system.
Technical details
The Crew HRM plugin for WordPress (versions 1.2.2 and below) contains a missing authorization vulnerability (CWE-862). The flaw exists because the plugin fails to properly validate user permissions or implement sufficient access control checks on certain functions. An authenticated attacker with basic 'Subscriber' level privileges can exploit this over the network to execute actions intended for higher-privileged users. This can result in unauthorized data modification or partial loss of availability. The issue is resolved in version 1.2.3.
Affected products
- Sekander Badsha Crew HRM <= 1.2.2
Timeline
- 2025-11-28: other: Reported by researcher benzdeus
- 2026-06-02: patched: Version 1.2.3 released
- 2026-06-02: disclosed: Public disclosure by Patchstack and NVD