CVE-2023-3547

The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly check nonce values in several actions, allowing an attacker to perform CSRF attacks.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:all_in_one_b2b_for_woocommerce_project:all_in_one_b2b_for_woocommerce:*:*:*:*:*:wordpress:*:*

History

07 Nov 2023, 04:18

Type Values Removed Values Added
CWE CWE-352

26 Sep 2023, 16:24

Type Values Removed Values Added
First Time All In One B2b For Woocommerce Project all In One B2b For Woocommerce
All In One B2b For Woocommerce Project
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:all_in_one_b2b_for_woocommerce_project:all_in_one_b2b_for_woocommerce:*:*:*:*:*:wordpress:*:*
References (MISC) https://wpscan.com/vulnerability/3cfb6696-18ad-4a38-9ca3-992f0b768b78 - (MISC) https://wpscan.com/vulnerability/3cfb6696-18ad-4a38-9ca3-992f0b768b78 - Exploit, Third Party Advisory

25 Sep 2023, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-25 16:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-3547

Mitre link : CVE-2023-3547

CVE.ORG link : CVE-2023-3547


JSON object : View

Products Affected

all_in_one_b2b_for_woocommerce_project

  • all_in_one_b2b_for_woocommerce
CWE

No CWE.