Revmakx develops WordPress management and backup plugins that are embedded across a large installed base of content-management sites, despite a narrow product portfolio. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the web-facing and privileged access context of WordPress administration tools and the appeal of WordPress sites as targets. The exposure recurs through information-disclosure, path-traversal, injection, and cross-site-scripting weaknesses that are characteristic of server-side web applications, particularly in backup and file-handling components where path validation and output encoding are critical; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Revmakx over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8856CRITICAL The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no | Nov 16, 2024 | 9.8 | 93 | NO | YES |
CVE-2020-8772CRITICAL The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administra | Feb 6, 2020 | 9.8 | 89 | NO | YES |
CVE-2016-15004CRITICAL A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation | Jul 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-42760HIGH Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Password Recovery Exploitation.This i | May 27, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-8996MEDIUM The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent | Jul 9, 2026 | 6.5 | 29 | NO | NO |
CVE-2024-38770CRITICAL Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This issue affects Backup and Stagin | Aug 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-2916MEDIUM The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow | Aug 15, 2023 | 5.3 | 27 | NO | NO |
CVE-2024-48020HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows SQL Injec | Oct 11, 2024 | 8.5 | 24 | NO | NO |
CVE-2021-25035MEDIUM The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a R | Jan 24, 2022 | 6.1 | 22 | NO | NO |
CVE-2024-49684HIGH Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue affects Backup and Staging by WP | Oct 23, 2024 | 7.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Revmakx.
Media articles that mention a CVE ID that affects a product developed by Revmakx — matched by CVE ID, not by vendor name.