
WP User Switch Security & Risk Analysis
wordpress.org/plugins/wp-user-switchWP User Switch is a very simple plugin which will help you to switch instantly between the user's account in a WordPress site.
Is WP User Switch Safe to Use in 2026?
Mostly Safe
Score 74/100WP User Switch is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The "wp-user-switch" plugin, despite its static analysis showing a seemingly low attack surface and good practices in terms of prepared statements and output escaping, presents significant security concerns due to its historical vulnerability data. The plugin has a history of 2 known CVEs, with one remaining unpatched. These past vulnerabilities, specifically 'Missing Authorization' and 'Authentication Bypass Using an Alternate Path or Channel', are critical indicators of potential weaknesses that could be exploited again. The fact that these types of vulnerabilities have occurred previously suggests potential systemic issues in how user roles and permissions are handled within the plugin. While the code signals like nonce and capability checks are present, their effectiveness is undermined by the past exploits that bypassed them. Therefore, the presence of an unpatched high-severity vulnerability and the recurring nature of critical vulnerability types should be a major red flag for users.
Key Concerns
- Unpatched high-severity CVE
- History of critical vulnerability types
- High percentage of properly escaped output
- Presence of nonce checks
- Presence of capability checks
WP User Switch Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP User Switch <= 1.1.0 - Authenticated (Subscriber+) Privilege Escalation
WP User Switch <= 1.0.2 - Authenticated (Subscriber+) Authentication Bypass via Cookie
WP User Switch Code Analysis
Output Escaping
Data Flow Analysis
WP User Switch Attack Surface
WordPress Hooks 11
Maintenance & Trust
WP User Switch Maintenance & Trust
Maintenance Signals
Community Trust
WP User Switch Alternatives
Passe-partout, login as a different user
passe-partout
The main administrators with their own password will be able to log in with whatever registered user account.
Login as User – Switch User & WooCommerce Login as Customer
one-click-login-as-user
Login as User plugin allows administrators to login as user, login user without password, switch user accounts, and login as customer in WooCommerce i …
UserMorph – Instant User Switching & Account Impersonation for WordPress
usermorph
Instant user-switching for WordPress. Morph into any account via a searchable admin bar menu securely and fast.
Switch User Login By Icegram
switch-user-login-by-icegram
User Switching Plugin allows administrators to quickly switch between user accounts in WordPress without logging
User Switching
user-switching
Instant switching between user accounts in WordPress and WooCommerce.
WP User Switch Developer Profile
3 plugins · 1K total installs
How We Detect WP User Switch
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-user-switch/assets/css/admin-main.css/wp-content/plugins/wp-user-switch/assets/css/main.css/wp-content/plugins/wp-user-switch/assets/js/main.js/wp-content/plugins/wp-user-switch/assets/js/main.jswp-user-switch/assets/css/admin-main.css?ver=wp-user-switch/assets/css/main.css?ver=wp-user-switch/assets/js/main.js?ver=HTML / DOM Fingerprints
wpus-user-logindata-wpus-user-iddata-wpus-noncewpus_localize