CVE-2025-47477
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Reflected XSS.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.23.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in WP Time Capsule plugin (≤1.22.23) allows attackers to inject scripts via crafted links.
Vulnerability
Type CVE-2025-47477 is a reflected cross-site scripting (XSS) vulnerability in the WordPress plugin Backup and Staging by WP Time Capsule (version ≤1.22.23). The flaw stems from improper neutralization of user input during web page generation, allowing an attacker to inject arbitrary HTML or JavaScript into a response [1].
Exploitation
Mechanism An attacker can trigger the vulnerability by crafting a malicious link containing the XSS payload. Successful exploitation requires a privileged user (e.g., an administrator) to click that link, visit a crafted page, or submit a specially designed form. No special network position is needed; the attack can be delivered via email, social media, or other channels [1].
Potential
Impact If exploited, the injected script executes in the context of the victim's browser, within the WordPress admin area. This could lead to session hijacking, defacement, redirection to malicious sites, or theft of sensitive data. The vulnerability is considered moderately dangerous and is expected to be used in mass-exploit campaigns targeting thousands of websites [1].
Mitigation
The vendor has released version 1.22.24 which fixes the vulnerability. Users are strongly advised to update immediately. If updating is not possible, implementing a virtual patch (such as the one provided by Patchstack) can block attacks until the plugin is updated [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <= 1.22.23
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.