CVE-2026-8996

MEDIUM

Backup And Staging BY WP Time Capsule < 1.22.26 - Information Exposure

Title source: rule
STIX 2.1

Description

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract download the most recently admin-decrypted SQL database backup, which typically contains password hashes, user credentials, and other sensitive site configuration data stored in the 'recent_decrypted_file' option. Exploitation requires that an administrator has previously performed a decrypt action, causing the decrypted SQL backup file to exist in the plugin's upload directory; without this prior admin action, there is no file to serve.

Scores

CVSS v3 6.5
EPSS 0.0026
EPSS Percentile 17.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
revmakx/Backup and Staging by WP Time Capsule < 1.22.26
Published Jul 09, 2026
Tracked Since Jul 09, 2026