Login as User or Customer

The WordPress plugin allows admins or customer support users to quickly switch between user accounts in one click, without needing the user's password. It includes features such as two-factor authentication support, managing user carts, and the ability to switch back to the original account. The plugin is compatible with WordPress, WordPress Multisite, and WooCommerce.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Authentication vulnerability in Login as User or Customer 3.8

    Open

    A plugin called "Login as User or Customer" for WordPress has a security issue in version 3.8. This means that someone could potentially access an administrator's account without the proper credentia...

    Read More
  • Authentication vulnerability in Login as User or Customer 3.8

    Open

    The Login as User or Customer plugin for WordPress is a security risk. It is vulnerable to a type of attack called authentication bypass, which affects all versions up to 3.8. This attack allows some...

    Read More
  • Access violation vulnerability in Login as User or Customer 3.2

    Fixed

    The Login as User or Customer plugin for WordPress has a security flaw that allows unauthenticated attackers to log in as administrators on the vulnerable site. This flaw is present in versions up to

    Read More
  • Input validation vulnerability in Login as User or Customer 1.9

    Fixed

    The Login as User or Customer Plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This is because the plugin is missing or incorrect nonce validation on the 'cp_...

    Read More
  • Access violation vulnerability in Login as User or Customer 1.8

    Fixed

    Low privileged users of the Login as User or Customer (User Switching) WordPress plugin before version 1.8 had the ability to use an AJAX action called 'cp_plugins_do_button_job_later_callback' to ins...

    Read More