Revmakx Revmakx

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Revmakx product.

RSS Feeds for Revmakx security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Revmakx products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Revmakx Sorted by Most Security Vulnerabilities since 2018

Revmakx Infinitewp Client6 vulnerabilities

Revmakx Wp Time Capsule2 vulnerabilities

Revmakx Local Sync1 vulnerability

Revmakx Wpcal1 vulnerability

By the Year

In 2026 there have been 4 vulnerabilities in Revmakx with an average score of 7.6 out of ten. Last year, in 2025 Revmakx had 4 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Revmakx in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.70.




Year Vulnerabilities Average Score
2026 4 7.60
2025 4 5.90
2024 4 7.85
2023 1 7.50
2022 2 7.95
2021 0 0.00
2020 1 0.00

It may take a day or so for new Revmakx vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Revmakx Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-74011 Aug 20, 2026
InfiniteWP Client 1.13.9 Blind SQLi via Improper Neutralization Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9.
Infinitewp Client
CVE-2026-8996 Jul 09, 2026
WP Time Capsule <=1.22.26 Sensitive Info Exposure via download_recent_decrypted_file The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract download the most recently admin-decrypted SQL database backup, which typically contains password hashes, user credentials, and other sensitive site configuration data stored in the 'recent_decrypted_file' option. Exploitation requires that an administrator has previously performed a decrypt action, causing the decrypted SQL backup file to exist in the plugin's upload directory; without this prior admin action, there is no file to serve.
CVE-2026-42760 May 27, 2026
Auth Bypass via Alt. Path WP Time Capsule <=1.22.25 Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Password Recovery Exploitation.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.25.
Wp Time Capsule
CVE-2026-1499 Feb 06, 2026
WP Duplicate <1.1.8 Missing Auth + Arbitrary File Upload RCE The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on the `process_add_site()` AJAX action combined with path traversal in the file upload functionality. This makes it possible for authenticated (subscriber-level) attackers to set the internal `prod_key_random_id` option, which can then be used by an unauthenticated attacker to bypass authentication checks and write arbitrary files to the server via the `handle_upload_single_big_file()` function, ultimately leading to remote code execution.
CVE-2025-66103 Dec 30, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Revmakx WPCal.Io Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Revmakx WPCal.Io allows DOM-Based XSS.This issue affects WPCal.Io: from n/a through 0.9.5.9.
Wpcal
CVE-2025-22280 Feb 27, 2025
DefendWP Firewall <=1.1.0: Missing Auth for Access Control (CVE-2025-22280) Missing Authorization vulnerability in revmakx DefendWP Firewall defend-wp-firewall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DefendWP Firewall: from n/a through <= 1.1.0.
Defend Wp Firewall
CVE-2025-24652 Jan 24, 2025
Revmakx WP Duplicate WP Migration Plugin v1.1.6: Missing Auth Missing Authorization vulnerability in revmakx WP Duplicate local-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Duplicate: from n/a through <= 1.1.6.
Local Sync
CVE-2024-10585 Jan 08, 2025
InfiniteWP Client <=1.13.0 Path Traversal via historyID The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.
Infinitewp Client
CVE-2024-8856 Nov 16, 2024
WP Time Capsule Plugin Arbitrary File Upload Vulnerability in UploadHandler.php The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Backup Staging By Wp Time Capsule
CVE-2024-49684 Oct 23, 2024
Deserialization of Untrusted Data in WP Time Capsule Backup & Staging 1.22.21 Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21.
Backup Staging By Wp Time Capsule
CVE-2024-48020 Oct 11, 2024
Revmakx WP Backup & Staging SQLi in Untreated Input (1.22.21) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows SQL Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21.
Wp Time Capsule
CVE-2023-6565 Feb 29, 2024
Sensitive Data Leak in InfiniteWP Client <1.12.3 (multi-call backup) The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.
Infinitewp Client
CVE-2023-2916 Aug 15, 2023
Sensitive Info Exposure in InfiniteWP Client 1.11.1 via admin_notice The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.
Infinitewp Client
CVE-2016-15004 Jul 23, 2022
A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0 A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection. The attack can be launched remotely. Upgrading to version 1.6.1.1 is able to address this issue. It is recommended to upgrade the affected component.
Infinitewp Client
CVE-2021-25035 Jan 24, 2022
The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
Backup Staging By Wp Time Capsule
CVE-2020-8772 Feb 06, 2020
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.
Infinitewp Client
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.