Mishubd's vulnerability footprint centers on a WordPress human resource management plugin, with observed weaknesses concentrated on authorization and access-control failures. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mishubd over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-5953HIGH The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee() and update_empoyee() function | Jul 4, 2025 | 8.8 | 25 | NO | NO |
CVE-2019-9573HIGH The WP Human Resource Management plugin before 2.2.6 for WordPress mishandles leave applications. | Mar 5, 2019 | 7.5 | 25 | NO | NO |
CVE-2025-5956HIGH The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authorization within the ajax_delete_employee() function in versions | Jul 4, 2025 | 8.1 | 22 | NO | NO |
CVE-2019-9574HIGH The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role. | Mar 5, 2019 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mishubd.
Media articles that mention a CVE ID that affects a product developed by Mishubd — matched by CVE ID, not by vendor name.