Executive brief
A security vulnerability exists in the WP Time Capsule plugin, which is used by WordPress site owners to manage backups and staging environments. This flaw allows an unauthorized person to bypass standard login procedures by exploiting the password recovery mechanism. If exploited, an attacker could gain unauthorized access to the website, potentially leading to the exposure of sensitive site data.
Technical details
The WP Time Capsule plugin for WordPress is vulnerable to an authentication bypass (CWE-288) via an alternate path or channel. The flaw resides in the password recovery mechanism, which can be exploited by a remote, unauthenticated attacker to bypass standard authentication controls. This issue affects versions up to and including 1.22.25. Successful exploitation allows an attacker to gain unauthorized access to the WordPress environment, potentially leading to data exfiltration or further site compromise. Users are advised to update to a version beyond 1.22.25 if available.
Affected products
- revmakx Backup and Staging by WP Time Capsule <= 1.22.25
Timeline
- 2026-05-27: advisory: NVD and Patchstack published the vulnerability details.