Extension WordPress
Vulnérabilités Backup and Staging by WP Time Capsule
Cette page rassemble les failles publiées pour Backup and Staging by WP Time Capsule, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Backup and Staging by WP Time Capsule
9 fiches
Backup and Staging by WP Time Capsule <= 1.22.26 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via download_recent_decrypted_file_wptc Function
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possible for authenticated attackers, with subscriber-level access…
*-1.22.26
1.22.27
08/07/2026
Backup and Staging by WP Time Capsule <= 1.22.25 – Missing Authorization
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.22.25. This makes it possible for…
*-1.22.25
1.22.26
30/05/2026
Backup and Staging by WP Time Capsule <= 1.22.23 – Reflected Cross-Site Scripting
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.22.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-1.22.23
1.22.24
04/06/2025
Backup and Staging by WP Time Capsule <= 1.22.21 – Unauthenticated Arbitrary File Upload
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up…
*-1.22.21
1.22.22
15/11/2024
Backup and Staging by WP Time Capsule <= 1.22.21 – Authenticated (Administrator+) PHP Object Injection
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.22.21 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level…
*-1.22.21
1.22.22
21/10/2024
Backup and Staging by WP Time Capsule <= 1.22.21 – Authenticated (Contributor+) SQL Injection
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.22.21 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-1.22.21
1.22.22
08/10/2024
Backup and Staging by WP Time Capsule <= 1.22.20 – Authentication Bypass to Account Takeover
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.22.20. This is due to wptc_decode_auth_token() function using a loose comparison. This makes it possible…
*-1.22.20
1.22.21
13/07/2024
Backup and Staging by WP Time Capsule <= 1.22.6 – Reflected Cross-Site Scripting
The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
*-1.22.6
1.22.7
21/12/2021
Backup and Staging by WP Time Capsule <= 1.21.15 – Authentication Bypass
The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.
[*, 1.21.16)
1.21.16
14/01/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.