← WordPress Vulnerabilities
WordPress security by component

Login as User or Customer

Login as User or Customer allows authorized administrators to temporarily log in as another WordPress user or customer.

Login as User or Customer (login-as-user-or-customer-user-switching) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Mar 11, 2024; the highest published CVSS base score is 9.8.

Plugin slug: login-as-user-or-customer-user-switching

CVE-2023-7247: Login as User or Customer: A security weakness

Login as User or Customer is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedMar 11, 2024
Safe version guidanceSee mitigation notes
Published vulnerabilities for login-as-user-or-customer-user-switching
Safe version
Mar 11, 2024 CVE-2023-7247
Login as User or Customer: A security weakness
Login as User or Customer is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.9
NVDPending
Jan 23, 2023 CVE-2022-4305
Login as User or Customer: A security weakness
Login as User or Customer is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
May 14, 2021 CVE-2021-24195
AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching): A security weakness
AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD8.8