Access violation vulnerability in Login as User or Customer 1.8

Low privileged users of the Login as User or Customer (User Switching) WordPress plugin before version 1.8 had the ability to use an AJAX action called ‘cp_plugins_do_button_job_later_callback’ to install plugins from the WordPress repository and activate arbitrary plugins on the blog. This vulnerability could potentially be exploited by attackers to install vulnerable plugins and potentially cause more serious problems

Detected in:

Login as User or Customer open vulnerable versions: >= * < 1.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.