Login as User or Customer [login-as-customer-or-user] <= 3.8 (unfixed + closed)
unknown
[en] Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.This issue affects Login as User or Customer (User Switching): from n/a through 3.8.
- Affected:
- up to 3.8
- Fix:
- No patched version reported
- Disclosed:
- Apr 25, 2024
CVE-2023-51484 on NVD →
Login as User or Customer [login-as-customer-or-user] <= 3.8 (unfixed + closed)
unknown
[en] The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site.
- Affected:
- up to 3.8
- Fix:
- No patched version reported
- Disclosed:
- Mar 11, 2024
CVE-2023-7247 on NVD →
Login as User or Customer <= 3.8 - Unauthenticated Limited Admin Account Compromise
high
The Login as User or Customer plugin for WordPress is vulnerable to admin account compromise in version 3.8. This is due to the plugin not validating that the user switching back to the administrative account is the user who initiated the original login as another user. This makes it possible for unauthenticated attack...
- CVSS:
- 8.1
- Affected:
- 3.8 – 3.8
- Fix:
- No patched version reported
- Disclosed:
- Feb 27, 2024
CVE-2023-7247 on NVD →
Login as User or Customer (User Switching) <= 3.8 - Authentication Bypass
critical
The Login as User or Customer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.8. This makes it possible for unauthenticated attackers to login as another user and escalate their privileges.
- CVSS:
- 9.8
- Affected:
- up to 3.8
- Fixed in:
- 3.9.1
- Disclosed:
- Dec 27, 2023
CVE-2023-51484 on NVD →
Login as User or Customer [login-as-customer-or-user] < 3.3 (closed)
unknown
[en] The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.
- Affected:
- up to 3.3
- Fixed in:
- 3.3
- Disclosed:
- Jan 23, 2023
CVE-2022-4305 on NVD →
Login as User or Customer <= 3.2 - Privilege Escalation
critical
The Login as User or Customer plugin for WordPress is vulnerable to authorization bypass due to improper authorization checks on the loginas_return_admin() function in versions up to, and including, 3.2. This makes it possible for unauthenticated attackers to log in as administrators on the vulnerable site. A similar v...
- CVSS:
- 9.8
- Affected:
- up to 3.2
- Fixed in:
- 3.3
- Disclosed:
- Dec 27, 2022
CVE-2022-4305 on NVD →
Login as User or Customer [login-as-customer-or-user] < 1.8 (closed)
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which h...
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- May 14, 2021
CVE-2021-24191 on NVD →
Login as User or Customer [login-as-customer-or-user] < 1.8 (closed)
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attac...
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- May 14, 2021
CVE-2021-24193 on NVD →
Login as User or Customer [login-as-customer-or-user] < 1.8 (closed)
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable p...
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- May 14, 2021
CVE-2021-24192 on NVD →
Login as User or Customer [login-as-customer-or-user] < 1.8 (closed)
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- May 14, 2021
CVE-2021-24195 on NVD →
Login as User or Customer [login-as-customer-or-user] < 1.8 (closed)
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which he...
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- May 14, 2021
CVE-2021-24194 on NVD →
Login as User or Customer [login-as-customer-or-user] < 1.8 (closed)
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which hel...
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- May 14, 2021
CVE-2021-24188 on NVD →
Login as User or Customer [login-as-customer-or-user] < 1.8 (closed)
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which...
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- May 14, 2021
CVE-2021-24189 on NVD →
Login as User or Customer [login-as-customer-or-user] < 1.8 (closed)
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- May 14, 2021
CVE-2021-24190 on NVD →
Login as User or Customer < 1.8 - Missing Authorization to Arbitrary Plugin Installation/Activation
high
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attac...
- CVSS:
- 8.8
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- Apr 22, 2021
CVE-2021-24195 on NVD →
Login as User or Customer <= 2.1 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
high
The Login as User or Customer Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attackers to install and act...
- CVSS:
- 8.8
- Affected:
- up to 1.9
- Fixed in:
- 2.1
- Disclosed:
- Apr 22, 2021
Login as User or Customer [login-as-customer-or-user] < 1.8 (closed)
unknown
Arbitrary Plugin Installation and Activation vulnerability discovered by Bugbang in WordPress Login as User or Customer (User Switching) plugin (versions <= 1.7).
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- Apr 22, 2021
Login as User or Customer [login-as-customer-or-user] < 2.1 (closed)
unknown
The Login as User or Customer Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attackers to install and act...
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Apr 22, 2021
Login as User or Customer [login-as-customer-or-user] < 2.1 (closed)
unknown
The "cp_plugins_do_button_job_later_callback" AJAX action, from multiple plugins of the WP-Buy vendor, was lacking CSRF check, allowing attackers to make a logged in administrator install and active arbitrary plugins (including specific version) from the WordPress repository which could lead to more critical...
- Affected:
- up to 2.1
- Fixed in:
- 2.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database