iqbalrony Vulnerabilities and Affected Products
Vulnerabilities associated with WP User Switch.
Products
Clear product- WP User Switch2 vulnerabilities
- wp_user_switch1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-37560HIGH | WordPress WP User Switch plugin <= 1.1.0 - Privilege Escalation vulnerabilityImproper Privilege Management vulnerability in IqbalRony WP User Switch allows Privilege Escalation.This issue affects WP User Switch: from n/a through 1.1.0. | CVSS8.0v3.1 | EPSS0.366% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2546HIGH | WP User Switch <= 1.0.2 - Authenticated (Subscriber+) Authentication Bypass via CookieThe WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2. This is due to incorrect authentication checking in the 'wpus_allow_user_to_admin_bar_menu' function with the 'wpus_who_switch' cookie value. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator, if they have access to the username. CWE-288Jun 6, 2023 | CVSS8.8v3.1 | EPSS1.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |