CVE-2026-6456

8.8

Account Switcher · Account Switcher (WordPress Plugin)

The Account Switcher WordPress plugin is vulnerable to improper authentication, allowing authenticated users to escalate privileges due to insufficient validation.

Executive summary

The Account Switcher WordPress plugin contains a critical privilege escalation vulnerability that permits authenticated users to gain unauthorized administrative access.

Vulnerability

This plugin is affected by an improper authentication flaw (CWE-287). An authenticated user can exploit this vulnerability to bypass intended access controls and escalate their privileges within the WordPress environment.

Business impact

With a CVSS score of 8.8, this vulnerability presents a high risk of total system compromise. An attacker who successfully escalates to administrator status can manipulate user accounts, steal sensitive data, and fully control the website, potentially leading to widespread data breaches and loss of organizational trust.

Remediation

Immediate Action: As there is no patch available, immediately deactivate and remove the Account Switcher plugin from all WordPress instances until a secure version is released by the developer.

Proactive Monitoring: Audit WordPress user roles and permissions for unauthorized changes or the creation of new administrative accounts.

Compensating Controls: Use a Web Application Firewall (WAF) to block unauthorized requests to the plugin's REST API endpoints, which are known vectors for this type of vulnerability.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this privilege escalation flaw requires immediate action. Administrators must remove the plugin from their production environments immediately and monitor for any signs of suspicious account activity or unauthorized privilege modification.

More Account Switcher CVEs