nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-49684 CVE-2024-49684
HIGH
WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.21 - PHP Object Injection vulnerability
Record summary
CVE-2024-49684 has a selected CVSS score of 7.2 (high).
Description
Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 23, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Backup and Staging by WP Time CapsuleBrowse revmakx / Backup and Staging by WP Time Capsulewp-time-capsuleDefault status: unaffected | CVE List | Through 1.22.21 | affected |
backup_and_staging_by_wp_time_capsuleBrowse revmakx / backup_and_staging_by_wp_time_capsuleDefault status: unknown | CVE List | Through 1.22.21 | affected |
References
3patchstack.comvdb entry
https://patchstack.com/database/Wordpress/Plugin/wp-time-capsule/vulnerability/wordpress-backup-and-staging-by-wp-time-capsule-plugin-1-22-21-php-object-injection-vulnerability?_s_id=cve patchstack.com
https://patchstack.com/database/vulnerability/wp-time-capsule/wordpress-backup-and-staging-by-wp-time-capsule-plugin-1-22-21-php-object-injection-vulnerability?_s_id=cve