CVE-2026-8996: Revmakx Backup And Staging By Wp Time Capsule

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract download the most recently admin-decrypted SQL database backup, which typically contains password hashes, user credentials, and other sensitive site configuration data stored in the 'recent_decrypted_file' option. Exploitation requires that an administrator has previously performed a decrypt action, causing the decrypted SQL backup file to exist in the plugin's upload directory; without this prior admin action, there is no file to serve.

Affected products

  • Revmakx Backup And Staging By Wp Time Capsule: up to and including 1.22.26

Published 2026-07-09. Last modified 2026-07-09.