CVE-2022-4305
Login as User or Customer < 3.3 - Unauthenticated Privilege Escalation to Admin
Record summary
CVE-2022-4305 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Login as User or CustomerDefault status: unaffected | CVE List | Before 3.3 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALLogin as User or Customer < 3.3 - Privilege EscalationCVSS 9.8
The plugin lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.
Impact
Unauthenticated attackers can obtain valid admin sessions by exploiting missing authorization checks in the Login as User or Customer plugin, potentially gaining complete control over the WordPress site and all user accounts.
Remediation
Fixed in version 3.3
Source: ProjectDiscovery