The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:56:47.204Z

Updated: 2024-01-16T15:56:47.204Z

Reserved: 2023-09-01T08:13:02.061Z


Link: CVE-2023-4703

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-16T16:15:13.300

Modified: 2024-01-23T19:38:18.610


Link: CVE-2023-4703

JSON object: View

cve-icon Redhat Information

No data.