Extension WordPress

Vulnérabilités Backup and Staging by WP Time Capsule

Cette page rassemble les failles publiées pour Backup and Staging by WP Time Capsule, leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
3Critiques
9Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Backup and Staging by WP Time Capsule

9 fiches

CVE-2026-8996 Moyenne · 6,5
Backup and Staging by WP Time Capsule

Backup and Staging by WP Time Capsule <= 1.22.26 – Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via download_recent_decrypted_file_wptc Function

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possible for authenticated attackers, with subscriber-level access…

Versions affectées

*-1.22.26

Correctif

1.22.27

Publication

08/07/2026

CVE-2025-47477 Moyenne · 6,1
Backup and Staging by WP Time Capsule

Backup and Staging by WP Time Capsule <= 1.22.23 – Reflected Cross-Site Scripting

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.22.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-1.22.23

Correctif

1.22.24

Publication

04/06/2025

CVE-2024-49684 Élevée · 7,2
Backup and Staging by WP Time Capsule

Backup and Staging by WP Time Capsule <= 1.22.21 – Authenticated (Administrator+) PHP Object Injection

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.22.21 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level…

Versions affectées

*-1.22.21

Correctif

1.22.22

Publication

21/10/2024

CVE-2024-38770 Critique · 9,8
Backup and Staging by WP Time Capsule

Backup and Staging by WP Time Capsule <= 1.22.20 – Authentication Bypass to Account Takeover

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.22.20. This is due to wptc_decode_auth_token() function using a loose comparison. This makes it possible…

Versions affectées

*-1.22.20

Correctif

1.22.21

Publication

13/07/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités