๐Ÿ” CVE Alert

CVE-2026-15240

HIGH 7.5

Customer Switching for WooCommerce < 2.1.3 - Customer+ Privilege Escalation to Administrator via Insecure Operator Resolution

CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
4th

The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any permitted account, including an administrator, resulting in full account takeover.

Vendor unknown
Product customer switching
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown customer switching

Be the first to know when new high vulnerabilities affecting unknown customer switching are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Customer Switching
0 < 2.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/4e5b9e2a-c8e0-41db-a989-1b44bc76c9d8/

Credits

Mike Gozdiskowski WPScan