CVE-2023-6741
MEDIUMDescription
The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address.
Is your site exposed to CVE-2023-6741?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| marvinlabs | wp_customer_area |
References
Frequently Asked Questions
What is CVE-2023-6741? +
How severe is CVE-2023-6741? +
What products are affected by CVE-2023-6741? +
How do I check if I'm vulnerable to CVE-2023-6741? +
Related Vulnerabilities
The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, …
The User Messages WordPress plugin through 1.2.4 does not sanitise and escape a parameter before outputting it back in the …
The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions …
The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers …
The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which …