WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier

Employees can easily clock in and out. Managers can run reports, keep track of employees/volunteers/contractors and their time.

5Reported vulnerabilities
6.5Highest CVSS score
2.0.4Latest version
600+Active installs

What to do now

Update All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier to 2.0.4 or later. 5 of these have a fixed version available. Updating resolves them.

Plugin last updated: November 1, 2025 / Tested up to WordPress: 6.8.8 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-11758 Medium 6.5 0.3% 0 to 2.0.3 (inclusive) 2.0.4 November 4, 2025
CVE-2025-6832 Medium 6.1 0.2% 2.0 and earlier 2.0.1 August 1, 2025
CVE-2022-44594 Medium 5.5 0.4% 1.3.320 and earlier 1.3.321 November 30, 2022
CVE-2025-6833 Medium 4.3 0.2% 2.0 and earlier 2.0.1 October 21, 2025
CVE-2025-46513 Medium 4.3 0.1% 1.3.325 and earlier 1.3.326 April 24, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.