LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2020-37255

Published
CVSS7.5
Severityhigh
WeaknessCWE-288
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the WordPress dashboard without providing credentials.

References

← Back to the CVE Tracker

Our coverage of CVE-2020-37255

No stories yet. This page updates automatically when we publish reporting that references CVE-2020-37255.