CVE-2023-51484 CRITICAL

CVE-2023-51484: WordPress Login as User or Customer plugin <= 3.8 - Unauthenticated Account Takeover vulnerability

Vendor Wp-Buy
Product Login as User or Customer (User Switching)
Weakness CWE-287 · Improper authentication
Published April 25, 2024
Last update April 28, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.This issue affects Login as User or Customer (User Switching): from n/a through 3.8.

Explanation of Vulnerability in Simple Terms

02Summary

The Login as User or Customer plugin for WordPress contains an authentication bypass vulnerability. An attacker can log in as any user, including administrators, without knowing their password. No special access or user interaction is required. This grants complete control over the WordPress site.

What an attacker can do

03Attacker Capabilities

Log in as any WordPress user, including administrators, without a password.

Potential impact on your site

04Site Impact

Complete compromise of the WordPress site; attacker gains admin access and can modify content, install malware, or delete data.

Conditions required to exploit

05Prerequisites

Network access to the WordPress login page. No authentication or user interaction required.

Key dates

06Disclosure timeline

April 25, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE