Impact
The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin is vulnerable to a stored cross‑site scripting flaw that allows authenticated users with plugin credentials to inject arbitrary scripts via the 'data' parameter. Because the plugin fails to properly escape or sanitize user input, injected malicious code is persisted and executed whenever an affected page is loaded, potentially compromising the confidentiality, integrity, and availability of the site or enabling session hijacking.
Affected Systems
The vulnerability affects the WordPress plugin Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for all releases up to version 1.3.1. Any WordPress site that has installed this plugin and has users with appropriate plugin permissions is susceptible to the flaw.
Risk and Exploitability
The CVSS score of 6.4 places the issue in the medium severity range, while an EPSS score below 1% indicates a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. The attack vector requires attackers to be authenticated with valid plugin credentials, so the vulnerability is limited to those with administrative or user‑level access to the plugin. Adopting the latest patch, disabling the plugin, or applying a content‑security policy can mitigate the risk.
OpenCVE Enrichment