PoC Index

CVE-2023-4703

HIGH 7.5EPSS 0.6%

The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
0.57% chance of exploitation in the next 30 days, 45th percentile
Published
2024-01-16
Updated
2025-06-20

Proof-of-concept exploits (1)

References

Related