WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.20 - Authentication Bypass and Privilege Escalation Vulnerability
CVE-2024-38770
9.8CRITICAL
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 1 August 2024
Summary
The vulnerability in WP Time Capsule's Backup and Staging feature arises from improper privilege management, allowing attackers to escalate privileges and bypass authentication mechanisms. This weakens security controls and potentially exposes sensitive data. Versions affected include 1.22.20 and below, necessitating prompt updates to safeguard against unauthorized access and exploitation.
Affected Version(s)
Backup and Staging by WP Time Capsule <= 1.22.20
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Credit
Dave Jong (Patchstack)