plugin

One Click Login As User Vulnerabilities

1 known security issue reported for the One Click Login As User WordPress plugin. Most recent disclosed Apr 14, 2026.

1 high

Running One Click Login As User on your site? Check whether your installed version is affected.

Scan your site free

Login as User <= 1.0.3 - Authenticated (Subscriber+) Privilege Escalation via 'oclaup_original_admin' Cookie

high

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-side verification that...

CVSS:
8.8
Affected:
up to 1.0.1
Fix:
No patched version reported
Disclosed:
Apr 14, 2026

CVE-2026-5617 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database