Fiche vulnérabilité
CVE-2023-3547 : faille élevée all in one b2b for woocommerce project… (CVSS 8.8)
Description
The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly check nonce values in several actions, allowing an attacker to perform CSRF attacks.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 25 sept. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- all in one b2b for woocommerce project all in one b2b for woocommerce