Executive brief
The Customer Switching WordPress plugin, which allows administrators to temporarily log in as other users for support purposes, contains a security flaw in how it manages these sessions. If an administrator switches to a customer's account, that customer can exploit the active session to gain the administrator's full permissions. This results in a complete takeover of the website, allowing the attacker to access sensitive data or modify site settings.
Technical details
The Customer Switching for WooCommerce plugin fails to properly validate the identity of the operator during an active user-switching session. When an administrator (operator) switches into a lower-privileged account, the plugin does not securely bind that session to the original administrator. Consequently, if the lower-privileged user is logged in simultaneously, they can resolve as the operator and use the plugin's functionality to switch into any other account, including an administrator account. This is achieved by exploiting an insecure operator resolution and a predictable or accessible nonce (usfw_kro_nonce). The vulnerability is fixed in version 2.1.3.
Affected products
- Unknown Customer Switching for WooCommerce < 2.1.3
Timeline
- 2026-07-10: disclosed
- 2026-07-30: advisory: NVD publication date