Impact
The All in One Time Clock Lite plugin for WordPress contains a missing authorization check that allows unauthenticated users to call admin‑level AJAX actions via wp_ajax_nopriv_ hooks. Because the code relies only on a nonce and performs no capability verification, an attacker can create new pages, generate shift records with integrity violations, and download time reports that include personally identifiable information such as employee names and work schedules. This flaw results in both a confidentiality breach of sensitive personnel data and an integrity compromise of content managed by the site.
Affected Systems
The vulnerability affects all releases of the codebangers All in One Time Clock Lite plugin for WordPress up to and including version 2.0.3. Websites running any of these versions are vulnerable. Plugins downloaded from the WordPress Plugin Repository up to that version are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity flaw, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Because the attack does not require any authentication or additional privileges, an attacker can exploit the flaw from any network‑accessible location by sending crafted AJAX requests to /wp-admin/admin‑ajax.php. The impact includes unauthorized content creation and disclosure of employee personal data.
OpenCVE Enrichment