CVE-2020-37255: WordPress Time Capsule 1.21.16 Authentication Bypass Vulnerability
WordPress Time Capsule Plugin version 1.21.16 contains a critical authentication bypass flaw. An attacker can send a specially crafted web request with a specific header to gain full administrator access to a WordPress site without knowing any password. This allows them to take complete control of the website and its contents.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-288
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-20 / 2026-06-23
NVD description (verbatim)
WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the WordPress dashboard without providing credentials.
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability is an authentication bypass in WordPress Time Capsule 1.21.16 stemming from improper session validation (CWE-288: Authentication Using a Known Password). The flaw allows unauthenticated attackers to craft a POST request containing the IWP_JSON_PREFIX header, which the application fails to properly validate. By exploiting this malformed header, an attacker can obtain a valid administrator session cookie and gain unauthorized access to the WordPress administrative dashboard without credential submission. The vulnerability requires network access only; no user interaction is needed.
Business impact
A compromised WordPress installation exposes your entire web presence to adversaries. An attacker with admin access can modify site content, inject malware, steal customer data, redirect traffic, harvest email addresses, deploy ransomware payloads, or use your server as a launching point for attacks on third parties. For e-commerce sites, this translates to potential payment card data theft and regulatory fines. Recovery requires forensic investigation, malware removal, credential reset across your organization, and customer notification—all costly and reputationally damaging.
Affected systems
This vulnerability affects WordPress installations running Time Capsule Plugin version 1.21.16. The plugin is commonly used for WordPress backups and site restoration. Any site running the affected version is at risk if the plugin remains unpatched. Sites with public-facing WordPress instances are immediately exposed to unauthenticated attacks.
Exploitability
This vulnerability presents high exploitability risk. The attack requires no authentication, no user interaction, and no complex preconditions—only network access to the target WordPress installation. An attacker can exploit this remotely and automatically with a simple HTTP POST request. The vulnerability is trivial to weaponize, making it a high-priority target for automated scanning and exploitation by commodity malware and opportunistic attackers.
Remediation
Immediately update WordPress Time Capsule to a patched version released after the vulnerability disclosure date of June 20, 2026. Verify the exact patched version against the official plugin repository or vendor advisory. If you are unsure whether your site runs this plugin, search your wp-content/plugins directory for 'time-capsule' or use a WordPress security scanner. After patching, conduct a full site audit for signs of unauthorized access, including reviewing WordPress admin user accounts for unfamiliar entries and checking server logs for suspicious POST requests.
Patch guidance
Access your WordPress admin dashboard and navigate to Plugins → Installed Plugins. Locate WordPress Time Capsule and check the current version against the plugin's official page on wordpress.org. If running version 1.21.16 or earlier, verify that a patched version is available from the vendor. Update through the WordPress admin interface if available, or manually download and reinstall the latest version from the official repository. Test the plugin's core functionality post-update. If automatic updates are not available immediately, consider temporarily deactivating the plugin until a fix is confirmed and deployed.
Detection guidance
Monitor web server logs for POST requests containing the 'IWP_JSON_PREFIX' header directed at your WordPress installation. Check WordPress user administration panels for unexpected administrator accounts created between June 20 and the date you patched. Review WordPress security audit logs (via security plugins like Wordfence or Sucuri) for unauthorized login events or privilege escalation attempts. Implement WordPress activity logging if not already in place. Search session and authentication logs for anomalous admin session cookies issued without corresponding login events.
Why prioritize this
This vulnerability scores 7.5 (HIGH) because it enables unauthenticated remote administrative compromise with no user interaction required and no complex prerequisites. The low attack complexity, widespread use of the Time Capsule plugin, and high confidentiality impact from gaining admin access make this a critical priority. Exploitation is trivial, and impacts are severe. Organizations running this plugin should treat patching as urgent.
Risk score, explained
The CVSS 3.1 score of 7.5 reflects: Network-accessible attack vector (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N), unchanged scope (S:U), and high confidentiality impact (C:H) with no integrity or availability impact (I:N, A:N). The high confidentiality impact derives from the ability to read all site data and configuration. The absence of integrity/availability impact in the CVSS vector does not diminish the threat—an attacker with admin access can perform arbitrary data modification and denial-of-service operations beyond what CVSS directly measures.
Frequently asked questions
How do I know if my WordPress site uses Time Capsule?
Log into your WordPress admin dashboard, go to Plugins → Installed Plugins, and search for 'Time Capsule.' If it appears in the list, you have it installed. You can also check the wp-content/plugins directory via SFTP or file manager for a folder named 'time-capsule' or similar. If you don't see it, the plugin is not active.
What should I do if I find this plugin is running but I don't remember installing it?
An attacker or a malicious third party may have installed it. Do not simply update it—this is a potential indicator of compromise. Immediately take the site offline or restrict access, consult a WordPress security professional, and conduct a full security audit before bringing it back online. Review all admin users and recent activity logs carefully.
Does patching this vulnerability alone secure my WordPress site?
Patching is essential but not sufficient. Conduct a post-patch audit for signs of unauthorized access, enforce strong passwords on all admin accounts, enable two-factor authentication, remove any unfamiliar admin users, and implement security hardening measures such as limiting login attempts and keeping all plugins, themes, and WordPress core updated. Consider a professional security assessment if you suspect prior compromise.
Is this vulnerability being actively exploited in the wild?
The vulnerability was disclosed on June 20, 2026, and is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. However, this does not mean it is not being exploited—threat intelligence may lag. The trivial nature of the attack makes exploitation likely once public details are available. Treat this as an urgent patching priority regardless of KEV status.
This analysis is provided for informational purposes based on published vulnerability data current as of the modification date (June 23, 2026). No exploit code is provided. Patch version numbers and exact remediation steps must be verified against the official WordPress Time Capsule plugin page and vendor advisories. Security impact and risk assessments are contextual and may vary based on your deployment environment, existing security controls, and threat landscape. Organizations should validate all findings in a controlled environment before applying changes to production systems. SEC.co does not warrant the accuracy or completeness of this information and recommends consultation with qualified security professionals for critical vulnerabilities. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2026-40780HIGHBookIt Authentication Bypass via Password Recovery
- CVE-2026-42654HIGHWP Swings Wallet System Authentication Bypass Allows Account Takeover
- CVE-2026-42668HIGHOmnisend Email Marketing WooCommerce Authentication Bypass (CVSS 7.5)
- CVE-2026-49062HIGHFaust.Js Authentication Bypass in Password Recovery (CVSS 8.8)
- CVE-2026-50194HIGHSteeltoe Management Endpoint Port-Bypass Authentication Flaw
- CVE-2026-5415HIGHWP Captcha PRO Authentication Bypass — Full Account Takeover Risk
- CVE-2026-56243HIGHCapgo API Key Hashing Bypass in PostgREST/RLS
- CVE-2026-8697HIGHTP-Link Archer C64 Unauthenticated Brute-Force SSH Vulnerability