Known CVE
Login as User or Customer < 3.3 - Privilege Escalation
The plugin lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.
CVE-2022-4305
Critical2022CVSS 9.8CWE-269
cve2022 · wpscan · wordpress · wp-plugin · wp · login-as-customer-or-user · auth-bypass · wp-buy
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website