Yes but only if the HR worker was running it themselves. If you mean their account could be compromised that's a serious problem, but a compromised employee account is already a pretty serious problem that good threat models take into account.
Public platforms are another matter, and that will be a new circle of hell.
Public platforms are another matter, and that will be a new circle of hell.