WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.20 - Authentication Bypass and Privilege Escalation Vulnerability
CVE-2024-38770
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2024
What is CVE-2024-38770?
The vulnerability in WP Time Capsule's Backup and Staging feature arises from improper privilege management, allowing attackers to escalate privileges and bypass authentication mechanisms. This weakens security controls and potentially exposes sensitive data. Versions affected include 1.22.20 and below, necessitating prompt updates to safeguard against unauthorized access and exploitation.
Affected Version(s)
Backup and Staging by WP Time Capsule <= 1.22.20