Clock In Portal <= 2.1 - Cross-Site Request Forgery To Staff Deletion
medium
The Clock In Portal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation when deleting staff members. This makes it possible for unauthenticated attackers to delete staff members via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Apr 18, 2023
CVE-2023-0761 on NVD →
Clock In Portal <= 2.1 - Cross-Site Request Forgery to Holidays Deletion
medium
The Clock In Portal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the delete action in the holidays.php file. This makes it possible for unauthenticated attackers to delete holidays via a forged request gra...
- CVSS:
- 4.3
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Apr 18, 2023
CVE-2023-0763 on NVD →
Clock In Portal <= 2.1 - Cross-Site Request Forgery to Designation Deletion
medium
The Clock In Portal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the delete action in the designations.php file. This makes it possible for unauthenticated attackers to delete designations via a forged req...
- CVSS:
- 4.3
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Apr 18, 2023
CVE-2023-0762 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database