Junglewise Threat Intelligence

CVE-2026-6456: BeycanPress Account Switcher privilege escalation in REST API

CVE-2026-6456 · Severity: high · CVSS 8.8 · Published 2026-05-20

Executive brief

The Account Switcher plugin for WordPress, which allows users to toggle between different accounts, contains a security flaw that allows low-level users to log in as any other user, including administrators. By exploiting this, an attacker can gain full control over the website, potentially leading to data theft, site defacement, or complete service disruption. The plugin has been temporarily removed from the WordPress repository due to this issue.

Technical details

The Account Switcher plugin (up to 1.0.2) is vulnerable to privilege escalation via the `rememberLogin` REST API endpoint. The vulnerability stems from a loose comparison (`!=`) used for secret validation in `app/RestAPI.php` and a lack of validation for empty secrets. If a target user has never used the 'Remember me' feature, their `asSecret` meta value defaults to an empty string; an attacker can provide an empty secret parameter to bypass the check and trigger `wp_set_auth_cookie()`. Furthermore, the REST routes lack capability checks by using `__return_true` for permission callbacks, allowing any authenticated user (Subscriber and above) to impersonate any other account, including Administrators.

Affected products

  • BeycanPress LLC Account Switcher Up to, and including, 1.0.2

Timeline

  • 2026-05-14: other: Plugin temporarily closed on WordPress.org repository
  • 2026-05-20: disclosed: NVD publication date

References