Privilege Escalation in Account Switcher Plugin for WordPress
CVE-2026-6456
8.8HIGH
What is CVE-2026-6456?
The Account Switcher plugin for WordPress contains a vulnerability that allows authenticated attackers to escalate their privileges. This issue arises because the plugin uses a loose comparison for secret validation in the rememberLogin REST API endpoint, allowing the passage of an empty secret parameter. As a result, attackers with Subscriber-level access can exploit this flaw to switch to any user account, including those with Administrative privileges. This represents a significant security concern, as it effectively enables unauthorized access to sensitive areas of the WordPress site.
Affected Version(s)
Account Switcher 0 <= 1.0.2