← back
CVE-2023-6824

WP Customer Area < 8.2.1 - Subscriber+ Account Address Leak

CVSS 6.5 MEDIUMEPSS 0.5%CWE-639
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
16 Jan 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →