CVE-2026-15240
7.5WordPress · Customer Switching for WooCommerce
The Customer Switching for WooCommerce plugin fails to secure user-switching sessions, allowing low-privileged accounts to escalate privileges and achieve full account takeover of administrators.
Executive summary
A high-severity authentication flaw in the Customer Switching for WooCommerce plugin allows attackers to perform full account takeover via improper session binding.
Vulnerability
This vulnerability involves improper authentication, where the plugin fails to bind an active user-switching session to the originating operator. An authenticated user with low privileges can leverage this flaw to impersonate an administrator and gain full control over the application.
Business impact
Successful exploitation allows an attacker to gain full administrative access to the WordPress environment. This leads to complete compromise of site data, unauthorized modification of configurations, and potential persistence mechanisms, justifying the high CVSS score of 8.8.
Remediation
Immediate Action: Update the Customer Switching for WooCommerce plugin to version 2.1.3 or later immediately.
Proactive Monitoring: Review WordPress user audit logs for unexpected administrative actions or anomalous login patterns originating from low-privileged accounts.
Compensating Controls: Deploy a Web Application Firewall to monitor for unusual session-switching patterns or unexpected privilege escalation attempts until the patch can be applied.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The risk of full account takeover necessitates immediate attention. Administrators must prioritize updating the Customer Switching for WooCommerce plugin to version 2.1.3 to close the authentication gap. Failure to remediate this vulnerability exposes the entire administrative backend to unauthorized access by any authenticated user.
More WordPress CVEs
Sources
Originally found and disclosed by Mike Gozdiskowski, with WPScan (coordinator), per the CVE Program record.