I believe if you set the privilege level of the snmp-server and related commands higher than the user's privilege level that should do the job. I just tried this and found it a bit tricky in practice. You might be able to get that to work with enoughtweaking.
I also tried (successfully) using the autocommand feature. Have the autocommand execute thus:
username six autocommand show run | ex host | address
However that does exclude all "ip address" lines, not just WAN ones. It will prevent the user from doing anything else though - they are logged out as soon as "show run" reached the end of the config.