Show plain JSON{"id": "CVE-2022-4305", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}, {"type": "Secondary", "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2023-01-23T15:15:14.283", "references": [{"url": "https://wpscan.com/vulnerability/286d972d-7bda-455c-a226-fd9ce5f925bd", "tags": ["Exploit", "Third Party Advisory"], "source": "contact@wpscan.com"}, {"url": "https://wpscan.com/vulnerability/286d972d-7bda-455c-a226-fd9ce5f925bd", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "descriptions": [{"lang": "en", "value": "The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session."}, {"lang": "es", "value": "El complemento Login as User or Customer de WordPress en sus versiones anteriores a la 3.3 carece de controles de autorizaci\u00f3n para garantizar que los usuarios puedan iniciar sesi\u00f3n como otro, lo que podr\u00eda permitir a atacantes no autenticados obtener una sesi\u00f3n de administrador v\u00e1lida."}], "lastModified": "2025-04-03T20:15:18.120", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:wp-buy:login_as_user_or_customer_\\(user_switching\\):*:*:*:*:*:wordpress:*:*", "vulnerable": true, "matchCriteriaId": "51547C08-ACD6-48E2-AEA3-47FEDBC9ED1C", "versionEndExcluding": "3.3"}], "operator": "OR"}]}], "sourceIdentifier": "contact@wpscan.com"}