Unrated severityNVD Advisory· Published Jun 20, 2026
WordPress Time Capsule Plugin 1.21.16 Authentication Bypass
CVE-2020-37255
Description
WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the WordPress dashboard without providing credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2= 1.21.16+ 1 more
- (no CPE)range: = 1.21.16
- (no CPE)range: = 1.21.16
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/47941mitreexploit
- www.vulncheck.com/advisories/wordpress-time-capsule-plugin-authentication-bypassmitrethird-party-advisory
- wptimecapsule.commitreproduct
News mentions
1- 25 WordPress Plugin CVEs Drop in Three Days: File Deletion, SSRF, and XSS Dominate the BatchVypr Intelligence · Jun 22, 2026