Authentication vulnerability in Login as User or Customer 3.8

A plugin called “Login as User or Customer” for WordPress has a security issue in version 3.8. This means that someone could potentially access an administrator’s account without the proper credentials. This happens because the plugin doesn’t check to make sure that the person switching back to the administrator account is actually the same person who originally logged in as someone else. This vulnerability can be exploited by hackers who are not logged in, but it would be difficult to do so. The attacker would need to know the IDs of both the administrator and the user they switched to, and may also use social engineering tactics.

Detected in:

Login as User or Customer open vulnerable versions: >= 3.8 <= 3.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.