CVE-2026-2720: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2720 is a missing authorization vulnerability in the Hr Press Lite plugin for WordPress that allows authenticated attackers with Subscriber-level access or above to retrieve sensitive employee data without proper authorization. The flaw affects all versions of the plugin up to and including 1.0.2, and was disclosed on March 21, 2026, with a fix available in version 1.0.3. It carries a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, Feedly).

Technical details

The root cause is a missing capability check (CWE-862) on the hrp-fetch-employees AJAX action handler registered in the plugin's HRP_Action.php file. Because no authorization check is performed before processing the AJAX request, any authenticated WordPress user — including those with the lowest default role (Subscriber) — can invoke this action and receive a full response containing employee records. The vulnerable code is visible in the plugin's source repository at includes/HRP_Action.php#L1444 and the AJAX action registration at admin/admin.php#L36 (Wordfence, WordPress Trac).

Impact

Successful exploitation exposes sensitive employee personally identifiable information (PII) and compensation data, including full names, email addresses, phone numbers, salary/pay rates, employment dates, and employment status. This data exposure creates significant privacy and compliance risks (e.g., GDPR, HIPAA) for organizations using the plugin to manage HR records. While integrity and availability are not directly impacted, the leaked salary and contact data could facilitate social engineering, phishing, or targeted attacks against employees (Wordfence).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a valid WordPress account at Subscriber level or above, making it accessible to any registered user on an affected site (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Hr Press Lite plugin (versions ≤ 1.0.2) using tools like WPScan or by checking the plugin's presence via /wp-content/plugins/hr-press-lite/.
  2. Obtain low-privilege access: Register or obtain credentials for any WordPress account with at least Subscriber-level access on the target site.
  3. Craft the AJAX request: Send an authenticated HTTP POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the action parameter set to hrp-fetch-employees, including the WordPress authentication cookies or nonce as required.
  4. Retrieve employee data: The server responds with a JSON payload containing sensitive employee records — names, emails, phone numbers, salaries, employment dates, and status — without any authorization enforcement (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Repeated or automated POST requests to /wp-admin/admin-ajax.php with action=hrp-fetch-employees from low-privilege user sessions or unusual IP addresses.
  • Logs: WordPress access logs showing authenticated requests to admin-ajax.php?action=hrp-fetch-employees from accounts that would not normally access HR data (e.g., Subscriber-role users); large response payloads returned to these requests.
  • Behavior: Unusual login activity from Subscriber-level accounts followed immediately by AJAX calls to the HR plugin endpoint, particularly outside business hours or from unexpected geolocations.

Mitigation and workarounds

The vendor (Codeclove) has released version 1.0.3 of the Hr Press Lite plugin, which addresses the missing capability check. Site administrators should update the plugin to version 1.0.3 or later immediately via the WordPress plugin dashboard. As an interim workaround, administrators can disable the plugin or restrict WordPress user registration to prevent untrusted users from obtaining Subscriber-level accounts until the patch is applied (Wordfence).

Community reactions

Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the week of March 16–22, 2026, noting the missing capability check and the availability of a patch in version 1.0.3. No significant broader media coverage or notable researcher commentary beyond the Wordfence advisory has been identified (Wordfence Blog).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management