CVE-2023-7247
MEDIUMDescription
The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site.
Is your site exposed to CVE-2023-7247?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| wp-buy | login_as_user_or_customer_\(user_switching\) |
References
Exploits
Frequently Asked Questions
What is CVE-2023-7247? +
How severe is CVE-2023-7247? +
What products are affected by CVE-2023-7247? +
How do I check if I'm vulnerable to CVE-2023-7247? +
Related Vulnerabilities
The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external …
Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Content Copy Protection & No Right Click wp-content-copy-protector allows Cross Site Request …
The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege …
The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back in …