VYPR

Customer Switching

by WordPress

CVEs (1)

  • CVE-2026-15240Jul 30, 2026
    risk 0.00cvss epss 0.00

    The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any…