The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-01-23T14:31:57.132Z

Updated:

Reserved: 2022-12-06T10:55:06.559Z


Link: CVE-2022-4305

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-01-23T15:15:14.283

Modified: 2023-11-07T03:57:29.827


Link: CVE-2022-4305

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.