The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.
History

Fri, 20 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:56:47.204Z

Updated: 2025-06-20T17:05:33.061Z

Reserved: 2023-09-01T08:13:02.061Z

Link: CVE-2023-4703

cve-icon Vulnrichment

Updated: 2024-08-02T07:37:59.271Z

cve-icon NVD

Status : Modified

Published: 2024-01-16T16:15:13.300

Modified: 2025-06-20T17:15:34.147

Link: CVE-2023-4703

cve-icon Redhat

No data.