
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2720 is a missing authorization vulnerability in the Hr Press Lite plugin for WordPress that allows authenticated attackers with Subscriber-level access or above to retrieve sensitive employee data without proper authorization. The flaw affects all versions of the plugin up to and including 1.0.2, and was disclosed on March 21, 2026, with a fix available in version 1.0.3. It carries a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, Feedly).
The root cause is a missing capability check (CWE-862) on the hrp-fetch-employees AJAX action handler registered in the plugin's HRP_Action.php file. Because no authorization check is performed before processing the AJAX request, any authenticated WordPress user — including those with the lowest default role (Subscriber) — can invoke this action and receive a full response containing employee records. The vulnerable code is visible in the plugin's source repository at includes/HRP_Action.php#L1444 and the AJAX action registration at admin/admin.php#L36 (Wordfence, WordPress Trac).
Successful exploitation exposes sensitive employee personally identifiable information (PII) and compensation data, including full names, email addresses, phone numbers, salary/pay rates, employment dates, and employment status. This data exposure creates significant privacy and compliance risks (e.g., GDPR, HIPAA) for organizations using the plugin to manage HR records. While integrity and availability are not directly impacted, the leaked salary and contact data could facilitate social engineering, phishing, or targeted attacks against employees (Wordfence).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a valid WordPress account at Subscriber level or above, making it accessible to any registered user on an affected site (Feedly).
/wp-content/plugins/hr-press-lite/./wp-admin/admin-ajax.php) with the action parameter set to hrp-fetch-employees, including the WordPress authentication cookies or nonce as required./wp-admin/admin-ajax.php with action=hrp-fetch-employees from low-privilege user sessions or unusual IP addresses.admin-ajax.php?action=hrp-fetch-employees from accounts that would not normally access HR data (e.g., Subscriber-role users); large response payloads returned to these requests.The vendor (Codeclove) has released version 1.0.3 of the Hr Press Lite plugin, which addresses the missing capability check. Site administrators should update the plugin to version 1.0.3 or later immediately via the WordPress plugin dashboard. As an interim workaround, administrators can disable the plugin or restrict WordPress user registration to prevent untrusted users from obtaining Subscriber-level accounts until the patch is applied (Wordfence).
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the week of March 16–22, 2026, noting the missing capability check and the availability of a patch in version 1.0.3. No significant broader media coverage or notable researcher commentary beyond the Wordfence advisory has been identified (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."