PT-2024-13401 · WordPress · All In One B2B For Woocommerce

Alexander Concha

·

Published

2024-01-16

·

Updated

2024-01-23

·

CVE-2023-4703

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The All in One B2B for WooCommerce WordPress plugin versions 1.0.0 through 1.0.3
Description The issue allows an unauthenticated attacker to update the details of any user due to improper validation of parameters when updating user details. This can lead to privilege escalation if the password of an Admin user is updated.
Recommendations For versions 1.0.0 through 1.0.3, update to a version that properly validates parameters when updating user details to prevent unauthorized user detail updates and potential privilege escalation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-4703

Affected Products

All In One B2B For Woocommerce