CVE-2022-4305
9.8
CRITICAL · CVSS 3.1 · EPSS 38.6% (pctl 99)
Patch early
EPSS 38.6% — above the 10% action threshold.
Description
The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 38.63% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2023-01-23 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| wp-buy | login as user or customer \(user switching\) |
References
→ the Explorer · watch your stack · NVD