cleantalk
Vulnerabilities and Security Researches

WP Customer Area, CVE-2023-6824

CVE, Research URL

CVE-2023-6824

Application

WP Customer Area

Published on
Jan 16, 2024
Research Description
The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address.
Affected versions
Min -, max 8.2.1.
Status
vulnerable