Impact
The WordPress PressTigers Universal Clocks plugin suffers from a missing authorization check that permits changes to clock settings without verifying the user’s role, a weakness described as CWE‑862. Based on the description, the likely attack vector is the plugin’s administrative or AJAX endpoints, a conclusion that is inferred rather than explicitly stated. An attacker who can reach these endpoints can therefore read or alter configuration values that should otherwise be protected behind role checks. By modifying these settings, an attacker could potentially expose sensitive data or disrupt the normal functioning of the site’s time‑display features.
Affected Systems
WordPress installations that have the PressTigers Universal Clocks plugin version 1.2.0 or older are vulnerable. The issue applies to all releases from the earliest available version through 1.2.0, regardless of site edition or host environment.
Risk and Exploitability
The vulnerability has a CVSS base score of 5.3, indicating moderate severity. The EPSS score is below 1 %, reflecting a low probability of widespread exploitation at this time. It is not listed in the CISA KEV catalog. The attack vector is inferred to be the plugin’s web interface, requiring no special privileges beyond network access to the site; an unauthenticated user may reach the vulnerable endpoints via crafted requests or a known path and will be able to bypass authorization checks.
OpenCVE Enrichment