ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37255”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37255
Published
2026-06-20
CVSS:
8.7
ShadowTrackr CVSS:
6.6
Summary:
WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the WordPress dashboard without providing credentials.