Input validation vulnerability in Clock In Portal- Staff & Attendance Management 2.1

The Clock In Portal plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery in versions up to, and including, 2.1. This vulnerability happens because of missing or incorrect security measures on the delete action in the designations.php file. This means that unauthenticated attackers can delete designations if they can get a site administrator to do something like click on a link.

Detected in:

Clock In Portal- Staff & Attendance Management fixed vulnerable versions: >= * <= 2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.