QID 730806
Date Published: 2023-05-22
QID 730806: WordPress Plugin Backup and Staging by WP Time Capsule Authentication Bypass Vulnerability
WP Time Capsule was created to ensure peace of mind with WP updates and put the fun back into WordPress.
CVE-2020-8771: Backup and Staging by WP Time Capsule prior to 1.21.16 is vulnerable to Authentication Bypass vulnerability.
Affected Versions:
Backup and Staging by WP Time Capsule WordPress plugin prior to 1.21.16
QID Detection Logic(Unauthenticated):
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Backup and Staging by WP Time Capsule WordPress plugin.
Successful exploitation of this vulnerability may allow an attacker to login as an administrator on the site due to logical mistakes in the code.
Solution
Customers are advised to install Backup and Staging by WP Time Capsule plugin version 1.21.16 or later version to remediate this vulnerability.
Vendor References
- Backup and Staging by WP Time Capsule Release Notes -
wordpress.org/plugins/wp-time-capsule/#developers
CVEs related to QID 730806
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Backup and Staging by WP Time Capsule |
|