Junglewise Threat Intelligence

CVE-2026-27351: Sekander Badsha Crew HRM missing authorization in access control

CVE-2026-27351 · Severity: medium · CVSS 5.4 · Published 2026-06-02

Executive brief

Crew HRM is a WordPress plugin used for managing human resources and employee data. A security flaw in the plugin's access control settings allows logged-in users with low-level permissions, such as subscribers, to perform actions they should not be authorized to do. This could lead to unauthorized changes to HR data or disruption of the management system.

Technical details

The Crew HRM plugin for WordPress (versions 1.2.2 and below) contains a missing authorization vulnerability (CWE-862). The flaw exists because the plugin fails to properly validate user permissions or implement sufficient access control checks on certain functions. An authenticated attacker with basic 'Subscriber' level privileges can exploit this over the network to execute actions intended for higher-privileged users. This can result in unauthorized data modification or partial loss of availability. The issue is resolved in version 1.2.3.

Affected products

  • Sekander Badsha Crew HRM <= 1.2.2

Timeline

  • 2025-11-28: other: Reported by researcher benzdeus
  • 2026-06-02: patched: Version 1.2.3 released
  • 2026-06-02: disclosed: Public disclosure by Patchstack and NVD

References