Privilege Escalation Vulnerability in wp-buy Login
CVE-2023-51484

9.8CRITICAL

What is CVE-2023-51484?

The vulnerability is related to improper authentication in the Login as User or Customer (User Switching) plugin, impacting versions up to 3.8. This issue may allow a malicious actor to perform unauthorized actions within a WordPress environment, potentially leading to privilege escalation. Website administrators are urged to review their security measures and ensure that this plugin is updated or mitigated to prevent exploitation.

Affected Version(s)

Login as User or Customer (User Switching) <= 3.8

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.