CVE-2022-4305
PoC —CVSS 3.1
9.8 critical
EPSS
39%p98
Published
()
Modified
Description
The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.
- Vendors
- wp-buy
- Products
- login as user or customer \(user switching\)
- Ecosystems
- WordPress
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.