WP Human Resource Management < 2.2.6 - Sensitive Information Disclosure
The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role. This allows any authenticated user to access sensitive user information, including hashed passwords, via the search_emp_leave_records action.
CVE-2019-9574 is a high severity with CVSS 7.5 Vulnerability issue affecting the Plugin WP Human Resource Management. It affects Versions before 2.2.6 and is fixed in 2.2.6.
CVE-2019-9574 is tracked for the Plugin WP Human Resource Management as high severity with CVSS 7.5. The affected range is Versions before 2.2.6. Update WP Human Resource Management to 2.2.6 or newer where that version is compatible with the site.
| Software Type | Plugin |
|---|---|
| Software Slug | |
| CVE | CVE-2019-9574 |
| Patched Versions |
2.2.6
|
| Affected Versions |
Versions before 2.2.6
|
Related CVEs for WP Human Resource Management
These internal links group the same WordPress plugin by CVE, issue type, severity, and patch status so operators and search engines can connect the full vulnerability cluster.
WP Human Resource Management 2.0.0 - 2.2.17 - Missing Authorization to Authenticated (Employee+) Privilege Escalation via wp_ajax_hrm_insert_employee AJAX Action
WP Human Resource Management Plugin < 2.2.6 - Authorization Bypass
WP Human Resource Management 2.0.0 - 2.2.17 - Missing Authorization to Authenticated (Employee+) Arbitrary User Deletion via ajax_delete_employee Function
This record contains material that is subject to copyright
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. Read more
License: CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy. Read more