Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Revmakx

First CVE: Feb 6, 2020Active for: 6 yearsTotal CVEs: 13
58.2
VTI Score
TOP TARGET

Revmakx develops WordPress management and backup plugins that are embedded across a large installed base of content-management sites, despite a narrow product portfolio. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the web-facing and privileged access context of WordPress administration tools and the appeal of WordPress sites as targets. The exposure recurs through information-disclosure, path-traversal, injection, and cross-site-scripting weaknesses that are characteristic of server-side web applications, particularly in backup and file-handling components where path validation and output encoding are critical; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Revmakx over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2020
6 years ago
Most Recent CVE
Jul 9, 2026
15 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-8856CRITICAL
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no
Nov 16, 20249.893NOYES
CVE-2020-8772CRITICAL
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administra
Feb 6, 20209.889NOYES
CVE-2016-15004CRITICAL
A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation
Jul 23, 20229.831NONO
CVE-2026-42760HIGH
Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Password Recovery Exploitation.This i
May 27, 20267.530NONO
CVE-2026-8996MEDIUM
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent
Jul 9, 20266.529NONO
CVE-2024-38770CRITICAL
Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This issue affects Backup and Stagin
Aug 1, 20249.827NONO
CVE-2023-2916MEDIUM
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow
Aug 15, 20235.327NONO
CVE-2024-48020HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows SQL Injec
Oct 11, 20248.524NONO
CVE-2021-25035MEDIUM
The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a R
Jan 24, 20226.122NONO
CVE-2024-49684HIGH
Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue affects Backup and Staging by WP
Oct 23, 20247.220NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
38%
31%
31%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low3 (23.1%)
High1 (7.7%)
None9 (69.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
15.4% of CVEs· 99th percentile
Nuclei
2 CVEs
15.4% of CVEs· 97th percentile
ExploitDB
1 CVE
7.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Revmakx.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Revmakx — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Revmakx's Products

View all 5 CNAs →

Top CWEs