Description
The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3. This is due to missing or incorrect nonce validation on several endpoints. This makes it possible for unauthenticated attackers to perform a variety of actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published: 2025-12-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-Site Request Forgery
Action: Patch
AI Analysis

Impact

The Time Sheets WordPress plugin is vulnerable to Cross‑Site Request Forgery in all releases up to and including 2.1.3. The flaw stems from missing or incorrect nonce validation on several endpoints, allowing an unauthenticated attacker to forge requests. An adversary could trick a site administrator into clicking a link or otherwise triggering a request that the plugin will process, leading to a variety of administrative actions without the administrator’s explicit consent. The impact is confined to the specific actions exposed by the plugin’s endpoints; it does not grant arbitrary code execution, elevate privileges, or directly compromise data integrity beyond the permitted operations.

Affected Systems

The vulnerability affects the WordPress plugin known as Time Sheets, developed by mrdenny, for any installation using a version of 2.1.3 or earlier. Administrators running these versions should verify the plugin version on their sites.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and an EPSS score of less than 1% suggests that exploitation of this weakness is unlikely in the broader attack landscape. The vulnerability is not listed in the CISA KEV catalog. Evasion requires an unauthenticated attacker to lure a legitimate administrator into performing a specific action, such as clicking a crafted link. This user‑interaction prerequisite significantly limits the practicality of exploitation.

Generated by OpenCVE AI on April 22, 2026 at 12:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Time Sheets plugin to the latest available version (2.1.4 or newer) which removes the nonce validation flaw.
  • If the plugin is not required, uninstall or disable it entirely to eliminate the attack surface.
  • Configure a site‑wide CSRF protection mechanism (such as a security plugin that enforces nonce checks globally) to guard against similar vulnerabilities in other extensions.

Generated by OpenCVE AI on April 22, 2026 at 12:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 05 Dec 2025 05:45:00 +0000

Type Values Removed Values Added
Description The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3. This is due to missing or incorrect nonce validation on several endpoints. This makes it possible for unauthenticated attackers to perform a variety of actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Title Time Sheets <= 2.1.3 - Cross-Site Request Forgery
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:59:29.182Z

Reserved: 2025-09-05T19:23:56.710Z

Link: CVE-2025-10055

cve-icon Vulnrichment

Updated: 2025-12-05T14:25:28.141Z

cve-icon NVD

Status : Deferred

Published: 2025-12-05T06:16:05.040

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-10055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T13:00:09Z

Weaknesses