VYPR
High severity7.1NVD Advisory· Published Jun 9, 2025· Updated Apr 23, 2026

CVE-2025-47477

CVE-2025-47477

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Reflected XSS.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.23.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in WP Time Capsule plugin (≤1.22.23) allows attackers to inject scripts via crafted links.

Vulnerability

Type CVE-2025-47477 is a reflected cross-site scripting (XSS) vulnerability in the WordPress plugin Backup and Staging by WP Time Capsule (version ≤1.22.23). The flaw stems from improper neutralization of user input during web page generation, allowing an attacker to inject arbitrary HTML or JavaScript into a response [1].

Exploitation

Mechanism An attacker can trigger the vulnerability by crafting a malicious link containing the XSS payload. Successful exploitation requires a privileged user (e.g., an administrator) to click that link, visit a crafted page, or submit a specially designed form. No special network position is needed; the attack can be delivered via email, social media, or other channels [1].

Potential

Impact If exploited, the injected script executes in the context of the victim's browser, within the WordPress admin area. This could lead to session hijacking, defacement, redirection to malicious sites, or theft of sensitive data. The vulnerability is considered moderately dangerous and is expected to be used in mass-exploit campaigns targeting thousands of websites [1].

Mitigation

The vendor has released version 1.22.24 which fixes the vulnerability. Users are strongly advised to update immediately. If updating is not possible, implementing a virtual patch (such as the one provided by Patchstack) can block attacks until the plugin is updated [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.