ZeroHour

CVE-2022-4305

PoC
CVSS 3.1
9.8 critical
EPSS
39%p98
Published
()
Modified
Description

The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.

Vendors
wp-buy
Products
login as user or customer \(user switching\)
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.