All in One B2B for WooCommerce <= 1.0.3 - Unauthenticated Privilege Escalation
CVE-2023-4703
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 16 January 2024
Badges
Summary
The All in One B2B for WooCommerce WordPress plugin version 1.0.3 contains a vulnerability that allows unauthenticated attackers to manipulate user data without proper parameter validation. By exploiting this flaw, an attacker can change user details, including the password of an Admin account, potentially leading to unauthorized administrative access. The inability of the plugin to effectively validate input during the user details update process poses significant security risks for WordPress installations utilizing this plugin.
Affected Version(s)
All in One B2B for WooCommerce 0 <= 1.0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved