Revmakx
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Revmakx product.
RSS Feeds for Revmakx security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Revmakx products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Revmakx Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 4 vulnerabilities in Revmakx with an average score of 7.6 out of ten. Last year, in 2025 Revmakx had 4 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Revmakx in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.70.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4 | 7.60 |
| 2025 | 4 | 5.90 |
| 2024 | 4 | 7.85 |
| 2023 | 1 | 7.50 |
| 2022 | 2 | 7.95 |
| 2021 | 0 | 0.00 |
| 2020 | 1 | 0.00 |
It may take a day or so for new Revmakx vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Revmakx Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-74011 | Aug 20, 2026 |
InfiniteWP Client 1.13.9 Blind SQLi via Improper NeutralizationImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9. |
|
| CVE-2026-8996 | Jul 09, 2026 |
WP Time Capsule <=1.22.26 Sensitive Info Exposure via download_recent_decrypted_fileThe Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the download_recent_decrypted_file_wptc. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract download the most recently admin-decrypted SQL database backup, which typically contains password hashes, user credentials, and other sensitive site configuration data stored in the 'recent_decrypted_file' option. Exploitation requires that an administrator has previously performed a decrypt action, causing the decrypted SQL backup file to exist in the plugin's upload directory; without this prior admin action, there is no file to serve. |
|
| CVE-2026-42760 | May 27, 2026 |
Auth Bypass via Alt. Path WP Time Capsule <=1.22.25Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Password Recovery Exploitation.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.25. |
|
| CVE-2026-1499 | Feb 06, 2026 |
WP Duplicate <1.1.8 Missing Auth + Arbitrary File Upload RCEThe WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on the `process_add_site()` AJAX action combined with path traversal in the file upload functionality. This makes it possible for authenticated (subscriber-level) attackers to set the internal `prod_key_random_id` option, which can then be used by an unauthenticated attacker to bypass authentication checks and write arbitrary files to the server via the `handle_upload_single_big_file()` function, ultimately leading to remote code execution. |
|
| CVE-2025-66103 | Dec 30, 2025 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Revmakx WPCal.IoImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Revmakx WPCal.Io allows DOM-Based XSS.This issue affects WPCal.Io: from n/a through 0.9.5.9. |
|
| CVE-2025-22280 | Feb 27, 2025 |
DefendWP Firewall <=1.1.0: Missing Auth for Access Control (CVE-2025-22280)Missing Authorization vulnerability in revmakx DefendWP Firewall defend-wp-firewall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DefendWP Firewall: from n/a through <= 1.1.0. |
|
| CVE-2025-24652 | Jan 24, 2025 |
Revmakx WP Duplicate WP Migration Plugin v1.1.6: Missing AuthMissing Authorization vulnerability in revmakx WP Duplicate local-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Duplicate: from n/a through <= 1.1.6. |
|
| CVE-2024-10585 | Jan 08, 2025 |
InfiniteWP Client <=1.13.0 Path Traversal via historyIDThe InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory. |
|
| CVE-2024-8856 | Nov 16, 2024 |
WP Time Capsule Plugin Arbitrary File Upload Vulnerability in UploadHandler.phpThe Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. |
|
| CVE-2024-49684 | Oct 23, 2024 |
Deserialization of Untrusted Data in WP Time Capsule Backup & Staging 1.22.21Deserialization of Untrusted Data vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Object Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21. |
|
| CVE-2024-48020 | Oct 11, 2024 |
Revmakx WP Backup & Staging SQLi in Untreated Input (1.22.21)Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows SQL Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21. |
|
| CVE-2023-6565 | Feb 29, 2024 |
Sensitive Data Leak in InfiniteWP Client <1.12.3 (multi-call backup)The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process. |
|
| CVE-2023-2916 | Aug 15, 2023 |
Sensitive Info Exposure in InfiniteWP Client 1.11.1 via admin_noticeThe InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges. |
|
| CVE-2016-15004 | Jul 23, 2022 |
A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection. The attack can be launched remotely. Upgrading to version 1.6.1.1 is able to address this issue. It is recommended to upgrade the affected component. |
|
| CVE-2021-25035 | Jan 24, 2022 |
The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin pageThe Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |
|
| CVE-2020-8772 | Feb 06, 2020 |
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.phpThe InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in. |
|