CVE-2024-43311 CRITICAL

CVE-2024-43311: WordPress Login As Users plugin <= 1.4.2 - Broken Authentication vulnerability

Vendor Geek Code Lab
Product Login As Users
Weakness CWE-269
Published August 19, 2024
Last update April 28, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2.

Explanation of Vulnerability in Simple Terms

02Summary

The Login As Users plugin for WordPress contains a privilege management flaw that allows unauthenticated attackers to gain unauthorized access to user accounts without requiring credentials. The vulnerability affects versions up to 1.4.2 and can be exploited remotely with no user interaction. Site administrators should update immediately to a version newer than 1.4.2.

What an attacker can do

03Attacker Capabilities

Log in as any user account on the site without knowing their password.

Potential impact on your site

04Site Impact

Any visitor can impersonate any user, including administrators, compromising all site data and functionality.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 19, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE