SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15240

HIGH · CVSS 7.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Customer Switching plugin for WordPress versions prior to 2.1.3 is vulnerable due to improper session binding, allowing lower-privileged users to impersonate the operator and switch to any permitted account, including those with administrative privileges. This flaw can lead to full account takeover, posing a significant security risk. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-15240
Severity
HIGH
CVSS
7.5
EPSS
0.20%
WordPress

Original NVD Description

The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any permitted account, including an administrator, resulting in full account takeover.