Description
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract download the most recently admin-decrypted SQL database backup, which typically contains password hashes, user credentials, and other sensitive site configuration data stored in the -recent_decrypted_file- option. Exploitation requires that an administrator has previously performed a decrypt action, causing the decrypted SQL backup file to exist in the plugin-s upload directory; without this prior admin action, there is no file to serve.
CVSS 6.5EPSS 0.262%Risque 0.67
Voir la source- Publication
- 2026-07-09 08:16:49
- Versions concernées
- <=1.22.26
- Type
- Application web
- Vecteur
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N