CVE-2024-8856: Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8856?
CVE-2024-8856 is considered a high severity vulnerability due to the ability to execute arbitrary file uploads.
How do I fix CVE-2024-8856?
To fix CVE-2024-8856, update the WP Time Capsule plugin to the latest version that is above 1.22.21.
What versions of WP Time Capsule are affected by CVE-2024-8856?
All versions of the WP Time Capsule plugin up to and including 1.22.21 are affected by CVE-2024-8856.
What impact does CVE-2024-8856 have on my website?
CVE-2024-8856 can allow attackers to upload malicious files to your website, potentially leading to further exploitation.
Is there a workaround for CVE-2024-8856 until I can update?
As a temporary workaround for CVE-2024-8856, disable the WP Time Capsule plugin until you can apply the necessary updates.