Description
The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is due to incorrect authentication checking in the 'IS_BA_Browse_As::notice' function with the 'is_ba_original_user_COOKIEHASH' cookie value. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator, if they have access to the user id.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
Any version
Timeline
| 2025-05-26: | Discovered |
| 2025-05-26: | Vendor Notified |
| 2025-05-29: | Disclosed |
Credits
István Márton
References
www.wordfence.com/...-0d54-4c44-b168-a886da1077cb?source=cve
plugins.trac.wordpress.org/...owse-as/tags/0.2/browse-as.php
plugins.trac.wordpress.org/...owse-as/tags/0.2/browse-as.php