PT-2025-37173 · WordPress · Time Tracker

Jonas Benjamin Friedli

·

Published

2025-09-11

·

Updated

2025-09-16

·

CVE-2025-9018

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Time Tracker plugin for WordPress versions through 3.1.0
Description: The Time Tracker plugin for WordPress is susceptible to unauthorized modification and data loss. A missing capability check within the tt update table function and tt delete record function functions allows authenticated attackers with Subscriber-level access or higher to update options, including user registration and default role settings. This could enable unauthorized users to register as Administrators and delete limited data from the database.
Recommendations: Update the Time Tracker plugin to a version beyond 3.1.0.

Fix

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-9018

Affected Products

Time Tracker