🔐 CVE Alert

CVE-2025-6833

MEDIUM 4.3

All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Clocking In/Out

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0 via the 'aio_time_clock_lite_js' AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber access and above, to clock other users in and out.

CWE CWE-639
Vendor codebangers
Product all in one time clock lite – tracking employee time has never been easier
Published Oct 22, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for codebangers all in one time clock lite – tracking employee time has never been easier

Be the first to know when new medium vulnerabilities affecting codebangers all in one time clock lite – tracking employee time has never been easier are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

codebangers / All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier
0 ≤ 2.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/c6c48173-ffe3-40f8-a2fa-cee66869e343?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3336943%40aio-time-clock-lite&new=3336943%40aio-time-clock-lite&sfp_email=&sfph_mail=

Credits

Jonas Benjamin Friedli