Description
Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through <= 1.2.0.
Published: 2026-07-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WordPress PressTigers Universal Clocks plugin suffers from a missing authorization check that permits changes to clock settings without verifying the user’s role, a weakness described as CWE‑862. Based on the description, the likely attack vector is the plugin’s administrative or AJAX endpoints, a conclusion that is inferred rather than explicitly stated. An attacker who can reach these endpoints can therefore read or alter configuration values that should otherwise be protected behind role checks. By modifying these settings, an attacker could potentially expose sensitive data or disrupt the normal functioning of the site’s time‑display features.

Affected Systems

WordPress installations that have the PressTigers Universal Clocks plugin version 1.2.0 or older are vulnerable. The issue applies to all releases from the earliest available version through 1.2.0, regardless of site edition or host environment.

Risk and Exploitability

The vulnerability has a CVSS base score of 5.3, indicating moderate severity. The EPSS score is below 1 %, reflecting a low probability of widespread exploitation at this time. It is not listed in the CISA KEV catalog. The attack vector is inferred to be the plugin’s web interface, requiring no special privileges beyond network access to the site; an unauthenticated user may reach the vulnerable endpoints via crafted requests or a known path and will be able to bypass authorization checks.

Generated by OpenCVE AI on August 1, 2026 at 10:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Universal Clocks plugin to the latest release that contains the most recent security patch.
  • If an upgrade cannot be performed immediately, deactivate or uninstall the plugin to remove the vulnerability from the active codebase.
  • Apply network or host‑based controls to limit access to the plugin’s administrative URLs, ensuring only users with the appropriate WordPress roles can reach those endpoints.

Generated by OpenCVE AI on August 1, 2026 at 10:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Presstigers
Presstigers universal Clocks
Wordpress
Wordpress wordpress
Vendors & Products Presstigers
Presstigers universal Clocks
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through <= 1.2.0.
Title WordPress Universal Clocks plugin <= 1.2.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Presstigers Universal Clocks
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:52:10.603Z

Reserved: 2026-06-25T08:04:53.458Z

Link: CVE-2026-57782

cve-icon Vulnrichment

Updated: 2026-07-13T13:52:07.694Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses