# CVE-2024-9593-Exploit
The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated attackers to execute code on the server. The invoked function's parameters cannot be specified.
## usage:
```
usage: CVE-2024-9593.py [-h] -u URL [-p PHPINFO]
CVE-2024-9593 Unauthenticated Remote Code Execution
options:
-h, --help show this help message and exit
-u URL, --url URL Target URL
-p PHPINFO, --phpinfo PHPINFO
Function or file path to exploit (default: phpinfo)
```
### pip install
```
pip install requests
```
### Note:
This script is provided for educational purposes only. The author is not responsible for any damages caused by the misuse of this script.
[4.0K] /data/pocs/20dee03923ca700f01996da3da3f41774600f051
├── [3.9K] CVE-2024-9593.py
└── [ 900] README.md
0 directories, 2 files