S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 29, 2024

CVE-2024-9593 Scanner

CVE-2024-9593 scanner - Remote Code Execution (RCE) vulnerability in Time Clock & Time Clock Pro

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-9593
8.3
CVSShigh
Exploitable remotely over the internet · no authentication required.

The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Time Clock Proby Scott Paterson
0
Time Clock – A WordPress Employee & Volunteer Time Clock Pluginby scottpaterson
0
time_clockby wpplugin
0
time_clock_proby wpplugin
0
Updated Sep 10, 2026View on NVD →
Detail

Time Clock and Time Clock Pro are WordPress plugins widely used by businesses to track employee work hours and manage schedules. These plugins are popular for integrating easily with WordPress-based websites, providing time management and attendance features. Companies use these plugins to simplify payroll and improve productivity. The plugins also offer customizable clock-in and clock-out functions for employee flexibility. Due to their integration with WordPress, vulnerabilities in these plugins can affect website security on multiple levels.

The vulnerability is a Remote Code Execution flaw that allows attackers to execute arbitrary code on the server. This exploit is facilitated by the ‘etimeclockwp_load_function_callback’ function, which does not require user authentication to initiate. As a result, it creates a serious risk of unauthorized access and malicious code execution. This type of flaw may allow attackers to compromise server integrity and security.

The vulnerability arises from the ‘etimeclockwp_load_function_callback’ function, which can be accessed without authentication and can execute PHP functions. Attackers can exploit this endpoint in the plugin by sending crafted requests to ‘/wp-admin/admin-ajax.php?action=etimeclockwp_load_function’ with malicious payloads. The function parameter in this request permits arbitrary function calls, leading to execution of unintended code on the server. This flaw does not filter or validate user inputs, leaving the server exposed to remote code injection. Exploiting this vulnerability could provide attackers with control over the server, escalating security risks.

Exploiting this vulnerability may allow unauthorized individuals to gain access to the server, execute arbitrary code, or manipulate website functionalities. This may lead to data theft, service disruptions, or further malware injections into the system. In severe cases, attackers may install backdoors or ransomware, compromising system integrity and leading to significant operational and financial damages.

Join S4E to get continuous, real-time insights into your digital assets' vulnerability status, all powered by our robust scanner. Protect your systems from evolving threats like Remote Code Execution by leveraging the comprehensive vulnerability management solutions that SecurityForEveryone provides. Sign up today to start proactive management of your security landscape with ease and efficiency.

References:

Solution Advice
  • Update Time Clock and Time Clock Pro plugins to the latest versions immediately.
  • Restrict access to ‘/wp-admin/admin-ajax.php’ to prevent unauthorized requests.
  • Implement a Web Application Firewall (WAF) to monitor and block malicious requests targeting vulnerable endpoints.
  • Regularly monitor plugin logs to detect unusual activity or potential exploit attempts.
  • Limit user permissions on the server to minimize potential damage from code execution vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-9593 scanner - Remote Code Execution (RCE) vulnerability in Time Clock & Time Clock Pro | S4E