WordPress Plugin Vulnerabilities

Login as User or Customer < 3.3 - Unauthenticated Privilege Escalation to Admin

Description

The plugin lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
David
Submitter
David
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2022-12-27 (about 2 years ago)
Added
2022-12-27 (about 2 years ago)
Last Updated
2022-12-27 (about 2 years ago)

Other