CVE-2026-15240
Customer Switching for WooCommerce < 2.1.3 - Customer+ Privilege Escalation to Administrator via Insecure Operator Resolution
CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
4th
The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any permitted account, including an administrator, resulting in full account takeover.
| Vendor | unknown |
| Product | customer switching |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown customer switching
Be the first to know when new high vulnerabilities affecting unknown customer switching are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Customer Switching
0 < 2.1.3
References
Credits
Mike Gozdiskowski WPScan