Access violation vulnerability in All in One B2B for WooCommerce 1.0.3

The All in One B2B for WooCommerce plugin for WordPress has a security vulnerability in versions up to and including 1.0.3. Attackers who are not authenticated (not logged in) are able to change the details of any user, such as their password, which can give them elevated privileges. This happens because there is not enough validation of certain parameters when updating user details.

Detected in:

All in One B2B for WooCommerce open vulnerable versions: >= * <= 1.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.