Medium 4.9 Unfixed
2024-03-11≤ 3.8
Login as User or Customer <= 3.8 - Admin Account Takeover
Minimum safe version
3.9.1
Update to 3.9.1 or later to address 13 fixable vulnerabilities
Login as User or Customer <= 3.8 - Admin Account Takeover
WordPress Login as User or Customer (User Switching) Plugin <= 3.8 is vulnerable to Privilege Escalation
CVE-2022-4305
Login as User or Customer <= 2.1 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
Multiple WP-Buy Plugins - Arbitrary Plugin Installation/Activation via CSRF
WordPress Login as User or Customer (User Switching) plugin <= 1.7 - Arbitrary Plugin Installation and Activation vulnerability
CVE-2021-24190
CVE-2021-24189
CVE-2021-24188
CVE-2021-24194
CVE-2021-24195
CVE-2021-24192
CVE-2021-24193
CVE-2021-24191