CVE-2020-37255
HIGHWordPress Time Capsule Plugin 1.21.16 Authentication Bypass
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37255. PoCs published by B. Canavate.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in WordPress Time Capsule Plugin versions prior to 1.21.16. It retrieves an admin cookie and optionally uploads a shell for remote command execution.
Description
WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the WordPress dashboard without providing credentials.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in WordPress Time Capsule Plugin versions prior to 1.21.16. It retrieves an admin cookie and optionally uploads a shell for remote command execution.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N