All in One Time Clock Lite
cpe:2.3:a:codebangers:all_in_one_time_clock_lite:*:*:*:*:wordpress:*:*
- <= 2.0
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the All in One Time Clock Lite WordPress plugin, in versions through 2.0. This vulnerability arises from inadequate validation of user-controlled keys in the 'aio_time_clock_lite_js' AJAX action. As a result, authenticated attackers with subscriber access or higher can manipulate the clock-in and clock-out times of other users.
Exploitation of this vulnerability allows authenticated users to arbitrarily clock other users in and out, potentially leading to unauthorized time tracking changes.
Users are advised to update the All in One Time Clock Lite WordPress plugin to version 2.0.1 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.