VYPR

Login As User Or Customer \(user Switching\)

by Wp Buy

CVEs (3)

  • CVE-2022-4305CriJan 23, 2023
    risk 0.67cvss 9.8epss 0.39

    The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.

  • CVE-2021-24195HigMay 14, 2021
    risk 0.57cvss 8.8epss 0.01

    Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary…

  • CVE-2023-7247MedMar 11, 2024
    risk 0.32cvss 4.9epss 0.01

    The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site.