The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other users account address.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wp_customer_area | Marvinlabs | * | 8.2.1 (excluding) |