The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:56:47.204Z

Updated: 2024-08-02T07:37:59.271Z

Reserved: 2023-09-01T08:13:02.061Z

Link: CVE-2023-4703

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-01-16T16:15:13.300

Modified: 2024-01-23T19:38:18.610

Link: CVE-2023-4703

cve-icon Redhat

No data.