Extension WordPress
Vulnérabilités Login as User or Customer , User Switching
Cette page rassemble les failles publiées pour Login as User or Customer , User Switching, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Login as User or Customer , User Switching
5 fiches
Login as User or Customer <= 3.8 – Unauthenticated Limited Admin Account Compromise
The Login as User or Customer plugin for WordPress is vulnerable to admin account compromise in version 3.8. This is due to the plugin not validating that the user switching back to the administrative account is the user…
3.8
Non indiqué
27/02/2024
Login as User or Customer (User Switching) <= 3.8 – Authentication Bypass
The Login as User or Customer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.8. This makes it possible for unauthenticated attackers to login as another user and escalate their privileges.
*-3.8
3.9.1
27/12/2023
Login as User or Customer <= 3.2 – Privilege Escalation
The Login as User or Customer plugin for WordPress is vulnerable to authorization bypass due to improper authorization checks on the loginas_return_admin() function in versions up to, and including, 3.2. This makes it possible for unauthenticated attackers to…
*-3.2
3.3
27/12/2022
Login as User or Customer < 1.8 – Missing Authorization to Arbitrary Plugin Installation/Activation
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate…
[*, 1.8)
1.8
22/04/2021
Login as User or Customer <= 2.1 – Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
The Login as User or Customer Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes…
*-1.9
2.1
22/04/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.