Description

The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.

INFO

Published Date :

2024-10-18T17:32:30.648Z

Last Modified :

2026-04-08T16:42:12.388Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2024-9593 vulnerability.

Vendors Products
Wpplugin
  • Time Clock
  • Time Clock Pro

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact