plugin

Wp Users Masquerade Vulnerabilities

1 known security issue reported for the Wp Users Masquerade WordPress plugin. Most recent disclosed Oct 9, 2024.

1 high

Running Wp Users Masquerade on your site? Check whether your installed version is affected.

Scan your site free

WP Users Masquerade <= 2.0.0 - Authenticated (Subscriber+) Authentication Bypass

high

The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect authentication and capability checking in the 'ajax_masq_login' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above,...

CVSS:
8.8
Affected:
up to 2.0.0
Fix:
No patched version reported
Disclosed:
Oct 9, 2024

CVE-2024-9522 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database