CVE-2023-6824: Marvinlabs Wp Customer Area

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address.

Affected products

  • Marvinlabs Wp Customer Area: before 8.2.1 (fixed in 8.2.1)

Published 2024-01-16. Last modified 2026-06-17.