Backup and Staging by WP Time Capsule
wp-time-capsule · plugin
Known security vulnerabilities for Backup and Staging by WP Time Capsule. Find out in seconds which version runs on your site with WP Lens.
7 known vulnerabilities
2 critical · 4 exploitable without logging in · 1 with public exploit code · latest Jul 9, 2026
Listed on wordpress.org · latest 1.22.27 · last updated Jun 10, 2026 · 10K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.8
CVE-2024-8856unauthenticated≤ 1.22.21
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
- Critical 9.8
CVE-2024-38770unauthenticated≤ 1.22.20
WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.20 - Authentication Bypass and Privilege Escalation Vulnerability
- High 8.5
CVE-2024-48020login required≤ 1.22.21
WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.21 - SQL Injection vulnerability
- High 7.5
CVE-2026-42760unauthenticated≤ 1.22.25
WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.25 - Broken Authentication vulnerability
- High 7.2
CVE-2024-49684high privilege≤ 1.22.21
WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.21 - PHP Object Injection vulnerability
- High 7.1
CVE-2025-47477unauthenticated · needs a click≤ 1.22.23
WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.23 - Reflected Cross Site Scripting (XSS) vulnerability
- Medium 6.5
CVE-2026-8996subscriber+≤ 1.22.26
Backup and Staging by WP Time Capsule <= 1.22.26 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via download_recent_decry
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).