← back
CVE-2024-9593highobserved exploitationCWE-94

Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution

83Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 8.3epss 12%
from disclosure to weapon0 days
Published on NVDOct 18
1st PoCOct 18
VulnCheck+144d
exploitation probability
12%top 4% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.