The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users account address.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wp_customer_area | Marvinlabs | * | 8.2.1 (excluding) |