johnbillion / user-switching

WordPress plugin that provides instant switching between user accounts.
https://wordpress.org/plugins/user-switching/
GNU General Public License v2.0
187 stars 49 forks source link

Switch back link not showing up after upgrading to Jetpack Version 8.1.1 #48

Closed catalasan closed 4 years ago

catalasan commented 4 years ago

After upgrading to Jetpack Version 8.1.1. The switch back link not showing up anymore and somehow the user that got switched are reporting that they are seeing the other user's info. This is a potential security issue.

johnbillion commented 4 years ago

Thanks for the report. There's a bug in Jetpack 8.1.1 which is causing this, several people on the forums have reported it.

Can you provide some more info about the user who's seeing another user's info? Who is seeing whose info?

catalasan commented 4 years ago

Our admin uses user-switching to help our users troubleshoot their issues a lot faster.

After the Jetpack upgrade, one user claim that when the admin user switch to his account while he was logged in he could see the admin's information as though the admin was logged in on his side. It seems that they swapped places.

I tried to replicate this issue with no luck. I have no idea how it happened to this one particular user who claim otherwise. I'm just worried it could happen again without us knowing about it.