
CVE-2026-2720 The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing capability check on the `hrp-fetch-employees` AJ… https://www.cve.org/CVERecord?id=CVE-2026-2720
Post summary
The CVE record reveals an unauthorized access flaw in the Hr Press Lite WordPress plugin caused by a missing capability check, yet no PoC, exploit, active use, or remediation is discussed.
