Privilege Escalation in WP Human Resource Management Plugin by WordPress
CVE-2025-5953

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 July 2025

What is CVE-2025-5953?

The WP Human Resource Management plugin for WordPress is susceptible to a privilege escalation vulnerability caused by inadequate authorization checks in the ajax_insert_employee() and update_employee() functions. Specifically, an attacker with Employee-level access could exploit the AJAX handler to assign themselves higher user roles, such as Administrator, without proper permissions. This vulnerability underscores the importance of thorough authorization checks when handling user roles within an application.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-5953 : Privilege Escalation in WP Human Resource Management Plugin by WordPress