The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly check nonce values in several actions, allowing an attacker to perform CSRF attacks.
History

Wed, 23 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-09-25T15:56:55.505Z

Updated: 2025-04-23T16:15:31.643Z

Reserved: 2023-07-07T17:30:38.839Z

Link: CVE-2023-3547

cve-icon Vulnrichment

Updated: 2024-08-02T07:01:55.906Z

cve-icon NVD

Status : Modified

Published: 2023-09-25T16:15:14.273

Modified: 2025-04-23T17:16:38.020

Link: CVE-2023-3547

cve-icon Redhat

No data.