Authentication vulnerability in WP User Switch 1.0.2

The WP User Switch plugin for WordPress is vulnerable to a security issue which allows someone with certain permissions to access the account of another user. This security issue is present in versions up to and including 1.0.2 of the plugin. The issue occurs because the ‘wpus_allow_user_to_admin_bar_menu’ function does not properly check the ‘wpus_who_switch’ cookie value. This means that someone with subscriber-level permissions or higher can access the account of another user, such as an administrator, if they have access to the username.

Detected in:

WP User Switch open vulnerable versions: >= * <= 1.0.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.