🔐 CVE Alert

CVE-2025-11758

MEDIUM 6.5

All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0.3 - Missing Authorization to Page Creation and Information Exposure

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization check in all versions up to, and including, 2.0.3. This is due to the plugin exposing admin-level AJAX actions to unauthenticated users via wp_ajax_nopriv_ hooks, while relying only on a nonce check without capability checks. This makes it possible for unauthenticated attackers to create published pages, create shift records with integrity issues, and download time reports containing PII (employee names and work schedules).

CWE CWE-862
Vendor codebangers
Product all in one time clock lite – tracking employee time has never been easier
Published Nov 4, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for codebangers all in one time clock lite – tracking employee time has never been easier

Be the first to know when new medium vulnerabilities affecting codebangers all in one time clock lite – tracking employee time has never been easier are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

codebangers / All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier
0 ≤ 2.0.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/28246279-ecd8-4731-a4cc-64a3a4167323?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/aio-time-clock-lite/tags/2.0.1/aio-time-clock-lite-actions.php#L26 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/aio-time-clock-lite/tags/2.0.1/aio-time-clock-lite-actions.php#L442 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/aio-time-clock-lite/tags/2.0.1/aio-time-clock-lite-actions.php#L1447 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3388144/

Credits

Athiwat Tiprasaharn