{"id":72119,"date":"2025-10-22T13:45:33","date_gmt":"2025-10-22T10:15:33","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-6833-all-in-one-time-clock-lite-tracking-employee-time-has-never-been-easier\/"},"modified":"2025-10-22T13:45:33","modified_gmt":"2025-10-22T10:15:33","slug":"cve-2025-6833-all-in-one-time-clock-lite-tracking-employee-time-has-never-been-easier","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-6833-all-in-one-time-clock-lite-tracking-employee-time-has-never-been-easier\/","title":{"rendered":"CVE-2025-6833 &#8211; All in One Time Clock Lite \u2013 Tracking Employee Time Has Never Been Easier"},"content":{"rendered":"<p>CVE ID : CVE-2025-6833<\/p>\n<p>Published :  Oct. 22, 2025, 10:15 a.m. | 27\u00a0minutes ago<\/p>\n<p>Description : The All in One Time Clock Lite \u2013 Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0 via the &#8216;aio_time_clock_lite_js&#8217; AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber access and above, to clock other users in and out.<\/p>\n<p>Severity: 4.3 | MEDIUM<\/p>\n<p>Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-6833 Published : Oct. 22, 2025, 10:15 a.m. | 27\u00a0minutes ago Description : The All in One Time Clock Lite \u2013 Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0 via the &#8216;aio_time_clock_lite_js&#8217; AJAX action due &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-72119","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/72119","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=72119"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/72119\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=72119"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=72119"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=72119"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}