The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://wordpress.org/plugins/hrm/#developers | third party advisory product |
http://www.openwall.com/lists/oss-security/2019/03/17/1 | mailing list |
http://www.securityfocus.com/bid/107464 | vdb entry third party advisory |