The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly check nonce values in several actions, allowing an attacker to perform CSRF attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-09-25T15:56:55.505Z

Updated: 2024-08-02T07:01:55.906Z

Reserved: 2023-07-07T17:30:38.839Z

Link: CVE-2023-3547

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-09-25T16:15:14.273

Modified: 2023-11-07T04:18:59.767

Link: CVE-2023-3547

cve-icon Redhat

No data.