PT-2026-42068 · WordPress · Account Switcher

Ren Voza

·

Published

2026-05-20

·

Updated

2026-05-28

·

CVE-2026-6456

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Account Switcher versions prior to 1.0.3
Description The Account Switcher plugin for WordPress allows authenticated attackers with Subscriber-level access or higher to escalate privileges to any user account, including Administrator. This occurs because the 'rememberLogin' REST API endpoint uses a loose comparison for secret validation and fails to verify that the secret is non-empty. If a target user has not used the Remember me feature, the asSecret user meta is empty, allowing an attacker to provide an empty secret parameter to bypass validation and trigger wp set auth cookie() for the target user. Furthermore, all REST routes utilize permission callback => ' return true', which bypasses necessary capability checks.
Recommendations Update the plugin to a version later than 1.0.2. As a temporary workaround, restrict access to the 'rememberLogin' REST API endpoint to minimize the risk of exploitation.

Fix

LPE

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-6456

Affected Products

Account Switcher