Input validation vulnerability in Time Clock Pro 1.1.4

The Time Clock and Time Clock Pro plugins for WordPress can be hacked by anyone, even without an account. This can happen in versions 1.2.2 (or older) for Time Clock and 1.1.4 (or older) for Time Clock Pro. The vulnerability is found in the ‘etimeclockwp_load_function_callback’ function, which lets hackers run their own code on the website’s server. Unfortunately, there is no way to control or prevent this function from being used.

Detected in:

Time Clock Pro fixed vulnerable versions: >= * <= 1.1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.