vendor:
Backup and Staging Plugin
by:
Al Baradi Joy
8.1
CVSS
CRITICAL
Arbitrary File Upload / Remote Code Execution
434
CWE
Product Name: Backup and Staging Plugin
Affected Version From: Up to and including 1.21.16
Affected Version To: 1.21.16
Patch Exists: YES
Related CWE: CVE-2024-8856
CPE: a:wp-timecapsule:backup_and_staging_plugin:1.21.16
Platforms Tested: WordPress
2025
WordPress Backup and Staging Plugin Arbitrary File Upload to Remote Code Execution
The WordPress plugin 'Backup and Staging by WP Time Capsule' up to version 1.21.16 allows unauthenticated attackers to upload arbitrary files via the upload.php endpoint, potentially leading to remote code execution by uploading and executing a PHP file directly from a specific directory.
Mitigation:
Ensure that the plugin is updated to version 1.21.17 or higher to mitigate this vulnerability.