CVE-2023-3547: All In One b2b For Woocommerce Project All In One b2b For Woocommerce

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly check nonce values in several actions, allowing an attacker to perform CSRF attacks.

Affected products

Published 2023-09-25. Last modified 2026-06-17.