peter bassill · operator
$ cve CVE-2022-4305 JSON

CVE-2022-4305

9.8
CRITICAL · CVSS 3.1 · EPSS 38.6% (pctl 99)

Patch early

EPSS 38.6% — above the 10% action threshold.

Description

The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS38.63% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploitnone known
Published2023-01-23
Last modified2026-06-17

Affected (1)

VendorProduct
wp-buylogin as user or customer \(user switching\)

References

→ the Explorer  ·  watch your stack  ·  NVD