What the vulnerability does
01Description
Improper Privilege Management vulnerability in IqbalRony WP User Switch allows Privilege Escalation.This issue affects WP User Switch: from n/a through 1.1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in IqbalRony WP User Switch allows Privilege Escalation.This issue affects WP User Switch: from n/a through 1.1.0.
Explanation of Vulnerability in Simple Terms
WP User Switch versions up to 1.1.0 contain a privilege management flaw that allows authenticated users to perform unauthorized actions. An attacker with low-level access can exploit this vulnerability by tricking a site administrator into clicking a malicious link, potentially gaining the ability to read sensitive data, modify site content, or disrupt service. Update to a version newer than 1.1.0 to resolve this issue.
What an attacker can do
Read sensitive data, modify site content, or disrupt service by exploiting improper privilege controls.
Potential impact on your site
Authenticated attackers can bypass privilege restrictions and perform actions they shouldn't be able to, compromising site integrity and confidentiality.
Conditions required to exploit
Attacker needs a low-privilege account on the site and must trick an admin into clicking a link.
Key dates
External resources
Related vulnerabilities