nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-38770 CVE-2024-38770
CRITICAL
WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.20 - Authentication Bypass and Privilege Escalation Vulnerability
Record summary
CVE-2024-38770 has a selected CVSS score of 9.8 (critical).
Description
Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.20.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 13, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 7, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Backup and Staging by WP Time CapsuleBrowse Revmakx / Backup and Staging by WP Time Capsulewp-time-capsuleDefault status: unaffected | CVE List | Through 1.22.20 | affected |
Revmakx Backup and StagingBrowse WP Time Capsule / Revmakx Backup and Staging | VulnCheck | Version data not supplied | |
backup_and_staging_by_wp_time_capsuleBrowse revmakx / backup_and_staging_by_wp_time_capsuleDefault status: unknown | CVE List | Through 1.22.20 | affected |
References
2patchstack.comvdb entry
https://patchstack.com/database/vulnerability/wp-time-capsule/wordpress-backup-and-staging-by-wp-time-capsule-plugin-1-22-20-authentication-bypass-and-privilege-escalation-vulnerability?_s_id=cve