CVE-2023-7247: Wp-Buy Login As User Or Customer (user Switching)

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site.

Affected products

  • Wp-Buy Login As User Or Customer (user Switching): up to and including 3.8

Published 2024-03-11. Last modified 2026-06-17.