Customer Switching < 2.1.3 - Authenticated (Customer+) Privilege Escalation
highThe Customer Switching for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 2.1.3 (exclusive). This makes it possible for authenticated attackers, with customer-level access and above, to switch and access other user's accounts, including administrators.
- CVSS:
- 8.8
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Jul 10, 2026