Login as User or Customer <= 3.2 - Privilege Escalation

2022-12-27 00:00
cydave

Strategic Overview

Status
Patched in 3.3
Affected Version<= 3.2
CVSS9.8Critical
CVECVE-2022-4305
View all Login as User or Customer — User Switching vulnerabilities

Vulnerability Overview

The Login as User or Customer plugin for WordPress is vulnerable to authorization bypass due to improper authorization checks on the loginas_return_admin() function in versions up to, and including, 3.2. This makes it possible for unauthenticated attackers to log in as administrators on the vulnerable site. A similar vulnerability is present in the my_action function which allows subscriber-level users and higher to log in as administrators.

Technical Analysis

REMEDIATION: Update to version 3.3, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C