Impact
The vulnerability is a missing authorization flaw in the BeastThemes Clockinator Lite plugin that permits exploitation of incorrectly configured access control levels. An attacker could gain unauthorized access to protected plugin functionality or data, enabling potential tampering or data disclosure within the WordPress site. The weakness is classified as incorrect authorization (CWE-862).
Affected Systems
WordPress installations that have the Clockinator Lite plugin version 1.0.9 or earlier installed are affected. Any site using these plugin versions is potentially vulnerable regardless of WordPress core or theme version.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity impact. The EPSS score of less than 1% suggests a low likelihood of widespread exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely a web-based request to the plugin’s endpoints, and the operation may require that the attacker either be able to craft a request that bypasses the plugin’s intended access level checks or that they have a user role with insufficient restriction.
OpenCVE Enrichment
EUVD