The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.
                
            References
                    | Link | Resource | 
|---|---|
| https://wpvulndb.com/vulnerabilities/10010 | Third Party Advisory | 
| https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/ | Exploit Third Party Advisory | 
| https://wpvulndb.com/vulnerabilities/10010 | Third Party Advisory | 
| https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/ | Exploit Third Party Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2020-02-06 17:15
Updated : 2024-11-21 05:39
NVD link : CVE-2020-8771
Mitre link : CVE-2020-8771
CVE.ORG link : CVE-2020-8771
JSON object : View
Products Affected
                wptimecapsule
- wp_time_capsule
 
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
