CVE Database
/

CVE-2023-4703

Back to search

CVE-2023-4703

Published: Jan 16, 2024

Modified: Jun 20, 2025

PUBLISHED

Description

The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.

VendorProductVersions

Unknown

All in One B2B for WooCommerce

affected
0 - <= 1.0.3

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now