High 7.1
2025-03-03< 3.2.0
CVE-2025-23843
Minimum safe version
3.2.0
Update to 3.2.0 or later to address 6 fixable vulnerabilities
CVE-2025-23843
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress WP-HR Manager: The Human Resources Plugin for WordPress Plugin <= 3.0.8 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress WP-HR Manager: The Human Resources Plugin for WordPress plugin < 3.0.3 - Sensitive Information Disclosure vulnerability
WordPress WP-HR Manager: The Human Resources Plugin for WordPress plugin < 3.0.3 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability