CVE-2024-43252 CRITICAL

CVE-2024-43252: WordPress Crew HRM plugin <= 1.1.1 - PHP Object Injection vulnerability

Vendor Crew Hrm
Product Crew HRM
Weakness CWE-502 · Unsafe deserialization
Published August 19, 2024
Last update April 28, 2026

CVSS base score

9.0/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1.

Explanation of Vulnerability in Simple Terms

02Summary

Crew HRM versions 1.1.1 and earlier are vulnerable to unsafe deserialization of untrusted data. An attacker can craft malicious serialized objects that, when processed by the application, execute arbitrary code on the server. This vulnerability requires network access but no authentication or user interaction, and can compromise the entire system including data confidentiality, integrity, and availability.

What an attacker can do

03Attacker Capabilities

Run arbitrary code on the server and take full control of the Crew HRM installation.

Potential impact on your site

04Site Impact

Complete compromise of Crew HRM data and server; attacker can read, modify, or delete all HR records and employee information.

Conditions required to exploit

05Prerequisites

Network access to the vulnerable Crew HRM instance; no authentication required.

Key dates

06Disclosure timeline

August 19, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE