CVE-2020-8771
WordPress Time Capsule < 1.21.16 - Authentication Bypass
Record summary
CVE-2020-8771 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALWordPress Time Capsule < 1.21.16 - Authentication BypassCVSS 9.8
WordPress Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.
Impact
An attacker can bypass authentication and gain unauthorized access to the WordPress Time Capsule plugin.
Remediation
Update WordPress Time Capsule plugin to version 1.21.16 or later.
Source: ProjectDiscovery