plugin

Clock In Portal Vulnerabilities

3 known security issues reported for the Clock In Portal WordPress plugin. Most recent disclosed Apr 18, 2023.

3 medium

Running Clock In Portal on your site? Check whether your installed version is affected.

Scan your site free

Clock In Portal <= 2.1 - Cross-Site Request Forgery To Staff Deletion

medium

The Clock In Portal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation when deleting staff members. This makes it possible for unauthenticated attackers to delete staff members via a forged request granted they can...

CVSS:
4.3
Affected:
up to 2.1
Fix:
No patched version reported
Disclosed:
Apr 18, 2023

CVE-2023-0761 on NVD →

Clock In Portal <= 2.1 - Cross-Site Request Forgery to Holidays Deletion

medium

The Clock In Portal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the delete action in the holidays.php file. This makes it possible for unauthenticated attackers to delete holidays via a forged request gra...

CVSS:
4.3
Affected:
up to 2.1
Fix:
No patched version reported
Disclosed:
Apr 18, 2023

CVE-2023-0763 on NVD →

Clock In Portal <= 2.1 - Cross-Site Request Forgery to Designation Deletion

medium

The Clock In Portal plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the delete action in the designations.php file. This makes it possible for unauthenticated attackers to delete designations via a forged req...

CVSS:
4.3
Affected:
up to 2.1
Fix:
No patched version reported
Disclosed:
Apr 18, 2023

CVE-2023-0762 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database