CVE-2023-4703
Last modified
CVE-2023-4703 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| All In One B2b For Woocommerce Project | All In One B2b For Woocommerce | <= 1.0.3 |
References
- https://wpscan.com/vulnerability/83278bbb-90e6-4465-a46d-60b4c703c11a/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/83278bbb-90e6-4465-a46d-60b4c703c11a/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-4703?
How severe is CVE-2023-4703?
How do I fix CVE-2023-4703?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-4702Authentication Bypass Using an Alternate Path or Channel vul…9.8
- CVE-2023-47020Multiple Cross-Site Request Forgery (CSRF) chaining in NCR T…8.8
- CVE-2023-47022Insecure Direct Object Reference in NCR Terminal Handler v.1…6.5
- CVE-2023-47024Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.…8.8
- CVE-2023-47025An issue in Free5gc v.3.3.0 allows a local attacker to cause…5.5
- CVE-2023-47029An issue in NCR Terminal Handler v.1.5.1 allows a remote att…9.8
- CVE-2023-47030An issue in NCR Terminal Handler v.1.5.1 allows a remote att…9.8
- CVE-2023-47031An issue in NCR Terminal Handler v.1.5.1 allows a remote att…9.8
- CVE-2023-47032Password Vulnerability in NCR Terminal Handler v.1.5.1 allow…9.8
- CVE-2023-47033MultiSigWallet 0xF0C99 was discovered to contain a reentranc…7.5
- CVE-2023-47034A vulnerability in UniswapFrontRunBot 0xdB94c allows attacke…7.5
- CVE-2023-47035RPTC 0x3b08c was discovered to not conduct status checks on …7.5
Are you affected by CVE-2023-4703?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
