Junglewise Threat Intelligence

CVE-2026-8996: WP Time Capsule sensitive information exposure in database backups

CVE-2026-8996 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Executive brief

A vulnerability in the WP Time Capsule plugin for WordPress allows low-level users to download sensitive database backups. These backups typically contain user credentials, password hashes, and private site configuration data. An exploit could lead to a full site takeover or the exposure of customer information if an administrator has recently decrypted a backup file.

Technical details

The WP Time Capsule plugin for WordPress suffers from a missing authorization check (CWE-862) in the 'download_recent_decrypted_file_wptc' function. This flaw allows authenticated attackers with subscriber-level permissions or higher to download the most recently decrypted SQL database backup file. The vulnerability is exploitable only if an administrator has previously performed a decryption action, leaving the decrypted file in the plugin's upload directory. The exposed SQL file contains sensitive data including password hashes and site configuration. The issue is present in versions up to and including 1.22.26.

Affected products

  • revmakx Backup and Staging by WP Time Capsule up to, and including, 1.22.26

Timeline

  • 2026-07-09: disclosed
  • 2026-07-09: advisory

References