Description
WordPress Plugin Login as User or Customer is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently install arbitrary plugins. WordPress Plugin Login as User or Customer version 1.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8 or latest
References
Related Vulnerabilities
MongoDb Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2021-32036)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-37909)
SharePoint Improper Input Validation Vulnerability (CVE-2019-0957)
WordPress Plugin Advanced post slider Unspecified Vulnerability (2.4.0)
Oracle Application Server Other Vulnerability (CVE-2004-2134)