{
    "id": "CVE-2022-4305",
    "published": "2023-01-23 15:15:14",
    "last_modified": "2026-06-17 05:20:32",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": null,
    "description": "The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.",
    "epss_score": "0.38625",
    "epss_percentile": "0.98539",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-02 18:17:36",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 38.6% — above the 10% action threshold."
    },
    "products": [
        {
            "vendor": "wp-buy",
            "product": "login_as_user_or_customer_\\(user_switching\\)"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://wpscan.com/vulnerability/286d972d-7bda-455c-a226-fd9ce5f925bd",
        "https://wpscan.com/vulnerability/286d972d-7bda-455c-a226-fd9ce5f925bd"
    ]
}