CVE-2026-42760: WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.25 - Broken Authentication vulnerability
Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Password Recovery Exploitation.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.25.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42760?
The severity of CVE-2026-42760 is rated as high with a score of 7.5.
How do I fix CVE-2026-42760?
To fix CVE-2026-42760, update the Revmakx Backup and Staging by WP Time Capsule plugin to version 1.22.26 or later.
What type of vulnerability is identified in CVE-2026-42760?
CVE-2026-42760 is an authentication bypass vulnerability, specifically affecting the password recovery functionality.
Which versions of the plugin are affected by CVE-2026-42760?
CVE-2026-42760 affects Backup and Staging by WP Time Capsule versions from n/a through 1.22.25.
What impact does CVE-2026-42760 have on users?
CVE-2026-42760 allows attackers to exploit the broken authentication mechanism to bypass authentication and compromise user accounts.