Report
The Login as User or Customer plugin for WordPress is vulnerable to authorization bypass due to improper authorization checks on the loginas_return_admin() function in versions up to, and including, 3.2. This makes it possible for unauthenticated attackers to log in as administrators on the vulnerable site. A similar vulnerability is present in the my_action function which allows subscriber-level users and higher to log in as administrators.
Score:8.6
Severity:High
Version:< 3.3
There is a patch available in v3.3 and we strongly recommend you update to this version as soon as possible.