What the vulnerability does
01Description
Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a through 1.4.2.
Explanation of Vulnerability in Simple Terms
The Login As Users plugin for WordPress contains a privilege management flaw that allows unauthenticated attackers to gain unauthorized access to user accounts without requiring credentials. The vulnerability affects versions up to 1.4.2 and can be exploited remotely with no user interaction. Site administrators should update immediately to a version newer than 1.4.2.
What an attacker can do
Log in as any user account on the site without knowing their password.
Potential impact on your site
Any visitor can impersonate any user, including administrators, compromising all site data and functionality.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities