← Back to CVE List

CVE-2022-4305

Published: 2023-01-23T15:15Z
Last Modified: 2025-04-03T20:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt