Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Reflected XSS.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.23.
Published: 2025-06-09
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Reflected Cross‑Site Scripting flaw that occurs when the plugin fails to neutralize user input properly before rendering it on a web page. Because the attacker can embed malicious JavaScript within a crafted URL, a victim who visits the URL will execute the script in their browser context, potentially stealing session cookies, defacing content, or executing further malicious actions. The affected code paths are limited to user‑controllable parameters that are reflected in the page output, so the impact is confined to the users who interact with the vulnerable page rather than the server itself.

Affected Systems

The element exposed by this flaw is the WordPress plugin “Backup and Staging by WP Time Capsule” from the vendor revmakx. Versions from the initial release through the last known vulnerable version 1.22.23 are affected. Users of earlier releases or later patched versions are not impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity level for a reflected XSS. However, the EPSS score is under 1 %, implying that the likelihood of this vulnerability being actively exploited in the wild is low. This issue is not listed in the CISA KEV catalog, further suggesting that it has not been targeted by known exploits to date. The attack vector is inferred to be remote and does not require authentication; a compromised or maliciously crafted link can deliver the payload to any user that visits the affected page.

Generated by OpenCVE AI on May 2, 2026 at 01:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin when the official fix is released
  • If an immediate update is not possible, remove or deactivate the plugin until a patched version is released
  • Check the plugin’s changelog frequently for additional security updates and ensure any custom code interacting with the plugin does not re‑inject unsanitized data

Generated by OpenCVE AI on May 2, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17516 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx Backup and Staging by WP Time Capsule allows Reflected XSS. This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.23.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx Backup and Staging by WP Time Capsule allows Reflected XSS. This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.23. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Reflected XSS.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.23.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00036}

epss

{'score': 0.00039}


Tue, 10 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx Backup and Staging by WP Time Capsule allows Reflected XSS. This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.23.
Title WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.23 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Revmakx Backup And Staging By Wp Time Capsule
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:42.304Z

Reserved: 2025-05-07T09:39:08.089Z

Link: CVE-2025-47477

cve-icon Vulnrichment

Updated: 2025-06-10T13:56:36.715Z

cve-icon NVD

Status : Deferred

Published: 2025-06-09T16:15:41.057

Modified: 2026-04-23T15:30:17.770

Link: CVE-2025-47477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T01:30:16Z

Weaknesses