Login as User or Customer — User Switching Security & Risk Analysis

wordpress.org/plugins/login-as-customer-or-user

Instant user switching for WordPress — switch to any user account in one click, with full WooCommerce support for customer service teams.

100 active installs v4.1.0 PHP 7.4+ WP 5.0+ Updated May 9, 2026
login-as-customerlogin-as-userswitch-useruser-switchingwoocommerce
70
B · Generally Safe
CVEs total5
Unpatched1
Last CVEFeb 27, 2024
Download
Safety Verdict

Is Login as User or Customer — User Switching Safe to Use in 2026?

Mostly Safe

Score 70/100

Login as User or Customer — User Switching is generally safe to use. 5 past CVEs were resolved.

5 known CVEs 1 unpatched Last CVE: Feb 27, 2024Updated 3mo ago
Risk Assessment

The "login-as-customer-or-user" v3.9.1 plugin presents a mixed security posture. While the static analysis indicates a relatively small attack surface with no unprotected entry points and a strong adherence to prepared statements for SQL queries, the plugin's history is a significant concern. The presence of 5 known CVEs, with 2 critically severe and unpatched vulnerabilities, suggests a pattern of recurring security flaws. These historical issues, including authentication bypass, improper authentication/authorization, and CSRF, highlight potential weaknesses in how the plugin handles user access and session management. Despite the current static analysis showing no critical taint flows and good output escaping, the past vulnerability record indicates that these aspects may have been compromised in previous versions, and the current version might still harbor latent risks or be susceptible to similar attack vectors.

Key Concerns

  • Unpatched Critical Vulnerabilities
  • Significant Vulnerability History (5 CVEs)
  • High rate of Critical/High severity CVEs
  • Potential for previously exploited vulnerabilities
Vulnerabilities
5 published

Login as User or Customer — User Switching Security Vulnerabilities

CVEs by Year

2 CVEs in 2021
2021
1 CVE in 2022
2022
1 CVE in 2023
2023
1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Critical
2
High
3

5 total CVEs

CVE-2023-7247high · 8.1Authentication Bypass Using an Alternate Path or Channel

Login as User or Customer <= 3.8 - Unauthenticated Limited Admin Account Compromise

Feb 27, 2024Unpatched
CVE-2023-51484critical · 9.8Improper Authentication

Login as User or Customer (User Switching) <= 3.8 - Authentication Bypass

Dec 27, 2023 Patched in 3.9.1 (867d)
CVE-2022-4305critical · 9.8Improper Authorization

Login as User or Customer <= 3.2 - Privilege Escalation

Dec 27, 2022 Patched in 3.3 (392d)
WF-c873d838-58e8-4f69-bccb-6d1de8d91877-login-as-customer-or-userhigh · 8.8Cross-Site Request Forgery (CSRF)

Login as User or Customer <= 2.1 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation

Apr 22, 2021 Patched in 2.1 (1006d)
CVE-2021-24195high · 8.8Missing Authorization

Login as User or Customer < 1.8 - Missing Authorization to Arbitrary Plugin Installation/Activation

Apr 22, 2021 Patched in 1.8 (1006d)
Code Analysis
Analyzed Apr 16, 2026

Login as User or Customer — User Switching Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
17
73 escaped
Nonce Checks
4
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

81% escaped90 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
my_action_javascript (admin/order-page.php:144)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Login as User or Customer — User Switching Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_my_action_loginasadmin/order-page.php:14
authwp_ajax_loginas_return_admintemplate.php:11
WordPress Hooks 19
filtermanage_edit-shop_order_columnsadmin/order-page.php:11
actionmanage_shop_order_posts_custom_columnadmin/order-page.php:12
actionadmin_footeradmin/order-page.php:13
actionrestrict_manage_postsadmin/order-page.php:15
actionadd_meta_boxesadmin/order-page.php:16
actionadmin_menuadmin/setting.php:10
actionadmin_initadmin/setting.php:11
actionadmin_print_stylesadmin/setting.php:396
filtermanage_users_columnsadmin/users.php:9
filtermanage_users_custom_columnadmin/users.php:10
filteradmin_headadmin/users.php:11
actionplugins_loadedloginas.php:55
actioninitloginas.php:296
filterplugin_row_metaloginas.php:330
actionadmin_initnotification.php:162
actionwp_footertemplate.php:9
actionwp_enqueue_scriptstemplate.php:10
actionwp_logouttemplate.php:12
filtershow_admin_bartemplate.php:13
Maintenance & Trust

Login as User or Customer — User Switching Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedMay 9, 2026
PHP min version7.4
Downloads14K

Community Trust

Rating60/100
Number of ratings13
Active installs100
Developer Profile

Login as User or Customer — User Switching Developer Profile

wp-buy

16 plugins · 345K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
850 days
View full developer profile
Detection Fingerprints

How We Detect Login as User or Customer — User Switching

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/login-as-customer-or-user/assets/css/loginas.css/wp-content/plugins/login-as-customer-or-user/assets/js/loginas.js
Script Paths
/wp-content/plugins/login-as-customer-or-user/assets/js/loginas.js
Version Parameters
login-as-customer-or-user/assets/css/loginas.css?ver=login-as-customer-or-user/assets/js/loginas.js?ver=

HTML / DOM Fingerprints

CSS Classes
loginas_button
Data Attributes
data-loginas-user-id
JS Globals
loginas_vars
FAQ

Frequently Asked Questions about Login as User or Customer — User Switching