Executive brief
The Universal Clocks plugin for WordPress, which allows site owners to display various time zones, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security levels and potentially modify settings or perform actions that should be restricted to administrators. While the impact is considered moderate, it could lead to unauthorized changes to how clocks and time information are displayed on the website.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the PressTigers Universal Clocks plugin for WordPress through version 1.2.0. The flaw stems from broken access control mechanisms that fail to properly validate user permissions before allowing access to certain functions or security levels. An unauthenticated remote attacker can exploit this by sending crafted requests to the affected site, potentially allowing them to execute actions or modify configurations that should require higher privileges. As of the advisory date, no official patch has been released, and the vulnerability affects all versions up to and including 1.2.0.
Affected products
- PressTigers Universal Clocks <= 1.2.0
Timeline
- 2026-01-04: other: Vulnerability reported by Legion Hunter
- 2026-07-02: advisory: Initial disclosure by Patchstack
- 2026-07-13: disclosed: CVE published to NVD dataset