PT-2024-9994 · WordPress · Time Clock Pro+1

István Márton

·

Published

2024-10-07

·

Updated

2025-01-20

·

CVE-2024-9593

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Time Clock plugin versions up to 1.2.2 Time Clock Pro plugin versions up to 1.1.4
Description: The issue concerns the etimeclockwp load function callback function, which is related to improper management of code generation. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified, enabling remote code execution.
Recommendations: For Time Clock plugin versions up to 1.2.2, update to a version later than 1.2.2 to resolve the issue. For Time Clock Pro plugin versions up to 1.1.4, update to a version later than 1.1.4 to resolve the issue. As a temporary workaround, consider disabling the etimeclockwp load function callback function until a patch is available.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-00120
CVE-2024-9593

Affected Products

Time Clock
Time Clock Pro