Extension WordPress

Vulnérabilités All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier

Cette page rassemble les failles publiées pour All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
6,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier

5 fiches

CVE-2025-11758 Moyenne · 6,5
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier

All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0.3 – Missing Authorization to Page Creation and Information Exposure

The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization check in all versions up to, and including, 2.0.3. This is due to the plugin exposing admin-level AJAX…

Versions affectées

*-2.0.3

Correctif

2.0.4

Publication

03/11/2025

CVE-2025-6833 Moyenne · 4,3
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier

All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0 – Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Clocking In/Out

The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0 via the 'aio_time_clock_lite_js' AJAX action…

Versions affectées

*-2.0

Correctif

2.0.1

Publication

21/10/2025

CVE-2025-6832 Moyenne · 6,1
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier

All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0 – Reflected Cross-Site Scripting

The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 2.0 due to…

Versions affectées

*-2.0

Correctif

2.0.1

Publication

01/08/2025

CVE-2022-44594 Moyenne · 5,5
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier

All in One Time Clok Lite <= 1.3.320 – Authenticated (Admin+) Stored Cross-Site Scripting

The All in One Time Clok Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up to, and including, 1.3.320 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.3.320

Correctif

1.3.321

Publication

30/11/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités