Vulnerability Details CVE-2020-8771
The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.836
EPSS Ranking 99.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-8771
-
cpe:2.3:a:wptimecapsule:wp_time_capsule:*