Insecure Direct Object Reference in All in One Time Clock Lite Plugin for WordPress
CVE-2025-6833

4.3MEDIUM

What is CVE-2025-6833?

The All in One Time Clock Lite plugin for WordPress is susceptible to an Insecure Direct Object Reference, impacting all versions up to and including 2.0. This vulnerability arises from insufficient validation on a user-controlled key within the 'aio_time_clock_lite_js' AJAX action. As a result, authenticated users with subscriber-level access and above can manipulate the system to clock other users in and out, potentially resulting in unauthorized time tracking and privacy violations.

Affected Version(s)

All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier * <= 2.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.