PT-2024-13401 · WordPress · All In One B2B For Woocommerce
Alexander Concha
·
Published
2024-01-16
·
Updated
2024-01-23
·
CVE-2023-4703
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
The All in One B2B for WooCommerce WordPress plugin versions 1.0.0 through 1.0.3
Description
The issue allows an unauthenticated attacker to update the details of any user due to improper validation of parameters when updating user details. This can lead to privilege escalation if the password of an Admin user is updated.
Recommendations
For versions 1.0.0 through 1.0.3, update to a version that properly validates parameters when updating user details to prevent unauthorized user detail updates and potential privilege escalation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
All In One B2B For Woocommerce