Unauthorized Access Vulnerability in All in One Time Clock Lite for WordPress
CVE-2025-11758
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 November 2025
What is CVE-2025-11758?
The All in One Time Clock Lite plugin for WordPress contains a security flaw that permits unauthorized access to administrative functions. This vulnerability arises from a lack of comprehensive authorization checks in all versions up to and including 2.0.3, exposing sensitive AJAX actions to unauthenticated users. Attackers can exploit this weakness to create published pages, manipulate shift records that could lead to integrity issues, and access time reports with personally identifiable information (PII) such as employee names and work schedules. The reliance solely on nonce checks without proper capability checks significantly increases the risk posed by this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
All in One Time Clock Lite β Tracking Employee Time Has Never Been Easier * <= 2.0.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved