plugin

Customer Area Vulnerabilities

22 known security issues reported for the Customer Area WordPress plugin. Most recent disclosed Jul 13, 2026.

3 high 9 medium

Running Customer Area on your site? Check whether your installed version is affected.

Scan your site free

WP Customer Area <= 8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'type' Shortcode Attribute

medium

The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `customer-area-protected-content` shortcode in all versions up to, and including, 8.3.5. This is due to insufficient input sanitization and output escaping on the shortcode attribute. This makes it pos...

CVSS:
6.4
Affected:
up to 8.3.5
Fixed in:
8.3.6
Disclosed:
Jul 13, 2026

CVE-2026-7640 on NVD →

WP Customer Area <= 8.3.4 - Authenticated (Custom+) Path Traversal

medium

The WP Customer Area plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 8.3.4. This makes it possible for authenticated attackers, with Custom-level access and above, to perform actions on files outside of the originally intended directory.

CVSS:
5.3
Affected:
up to 8.3.4
Fixed in:
8.3.5
Disclosed:
May 1, 2026

CVE-2026-42661 on NVD →

WP Customer Area <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Read/Deletion via ajax_attach_file

high

The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_attach_file' function in all versions up to, and including, 8.3.4. This makes it possible for authenticated attackers with a role that an administrator grants access to (e.g....

CVSS:
8.8
Affected:
up to 8.3.4
Fixed in:
8.3.5
Disclosed:
Apr 17, 2026

CVE-2026-3464 on NVD →

WP Customer Area [customer-area] <= 8.2.7 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in aguilatechnologies WP Customer Area customer-area allows PHP Local File Inclusion.This issue affects WP Customer Area: from n/a through <= 8.2.7.

Affected:
up to 8.2.7
Fix:
No patched version reported
Disclosed:
Nov 6, 2025

CVE-2025-60201 on NVD →

Customer Area < 8.3.4 - Unauthenticated Local File Inclusion

high

The Customer Area plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 8.3.4. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access contro...

CVSS:
8.1
Affected:
up to 8.3.4
Fixed in:
8.3.4
Disclosed:
Jul 21, 2025

CVE-2025-60201 on NVD →

WP Customer Area [customer-area] <= 8.2.5 (unfixed)

unknown

[en] Missing Authorization vulnerability in aguilatechnologies WP Customer Area allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Customer Area: from n/a through 8.2.5.

Affected:
up to 8.2.5
Fix:
No patched version reported
Disclosed:
Jun 20, 2025

CVE-2025-49982 on NVD →

WP Customer Area <= 8.2.5 - Missing Authorization

medium

The WP Customer Area plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 8.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 8.2.5
Fix:
No patched version reported
Disclosed:
Jun 19, 2025

CVE-2025-49982 on NVD →

WP Customer Area [customer-area] < 8.2.5

unknown

[en] The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

Affected:
up to 8.2.5
Fixed in:
8.2.5
Disclosed:
Jan 27, 2025

CVE-2024-12436 on NVD →

WP Customer Area [customer-area] < 8.2.5

unknown

[en] The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack

Affected:
up to 8.2.5
Fixed in:
8.2.5
Disclosed:
Jan 27, 2025

CVE-2024-12280 on NVD →

WP Customer Area <= 8.2.4 - Cross-Site Request Forgery to Event Log Deletion

medium

The WP Customer Area plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.2.4. This is due to missing or incorrect nonce validation on the 'wpca-logs' page. This makes it possible for unauthenticated attackers to delete event logs via a forged request granted they can...

CVSS:
4.3
Affected:
up to 8.2.4
Fixed in:
8.2.5
Disclosed:
Jan 6, 2025

CVE-2024-12280 on NVD →

WP Customer Area <= 8.2.4 - Cross-Site Request Forgery to Bulk Deletion

medium

The WP Customer Area plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.2.4. This is due to missing or incorrect nonce validation on the 'cuar-trash' action. This makes it possible for unauthenticated attackers to delete customer files via a forged request granted t...

CVSS:
4.3
Affected:
up to 8.2.4
Fixed in:
8.2.5
Disclosed:
Jan 6, 2025

CVE-2024-12436 on NVD →

WP Customer Area [customer-area] < 8.2.3

unknown

[en] The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

Affected:
up to 8.2.3
Fixed in:
8.2.3
Disclosed:
Jan 24, 2024

CVE-2024-0665 on NVD →

WP Customer Area <= 8.2.2 - Reflected Cross-Site Scripting

medium

The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

CVSS:
6.1
Affected:
up to 8.2.2
Fixed in:
8.2.3
Disclosed:
Jan 23, 2024

CVE-2024-0665 on NVD →

WP Customer Area [customer-area] < 8.2.1

unknown

[en] The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address.

Affected:
up to 8.2.1
Fixed in:
8.2.1
Disclosed:
Jan 16, 2024

CVE-2023-6741 on NVD →

WP Customer Area [customer-area] < 8.2.1

unknown

[en] The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address.

Affected:
up to 8.2.1
Fixed in:
8.2.1
Disclosed:
Jan 16, 2024

CVE-2023-6824 on NVD →

WP Customer Area <= 8.2.1 - Insecure Direct Object Reference to Address Modification

medium

The WP Customer Area plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_address_for_owner function in all versions up to, and including, 8.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify address...

CVSS:
4.3
Affected:
up to 8.2.0
Fixed in:
8.2.1
Disclosed:
Jan 10, 2024

CVE-2023-6741 on NVD →

WP Customer Area <= 8.2.0 - Insecure Direct Object Reference to Account Address Disclosure

medium

The WP Customer Area plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_load_address_from_owner() function in all versions up to, and including, 8.2.0. This makes it possible for authenticated attackers with subscriber-level access and above, to retrieve othe...

CVSS:
4.3
Affected:
up to 8.2.0
Fixed in:
8.2.1
Disclosed:
Jan 10, 2024

CVE-2023-6824 on NVD →

WP Customer Area [customer-area] < 8.1.4

unknown

[en] The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.

Affected:
up to 8.1.4
Fixed in:
8.1.4
Disclosed:
Feb 13, 2023

CVE-2022-4745 on NVD →

WP Customer Area <= 8.1.3 - Cross-Site Request Forgery

high

The WP Customer Area plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.1.3. This is due to missing or incorrect nonce validation on several functions related to file and folder management. This makes it possible for unauthenticated attackers to invoke those functions v...

CVSS:
8.8
Affected:
up to 8.1.3
Fixed in:
8.1.4
Disclosed:
Jan 17, 2023

CVE-2022-4745 on NVD →

WP Customer Area [customer-area] < 7.4.3

unknown

[en] The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.

Affected:
up to 7.4.3
Fixed in:
7.4.3
Disclosed:
Aug 20, 2019

CVE-2017-18519 on NVD →

WP Customer Area [customer-area] < 7.4.3

unknown

The value of $_REQUEST[‘page’] parameter is not escaped in the template files - /src/php/core-addons/admin-area/templates/. This allows an attacker to execute a reflected cross site scripting attack. The vulnerability was fixed in version 7.4.3.

Affected:
up to 7.4.3
Fixed in:
7.4.3
Disclosed:
Nov 27, 2017

WP Customer Area <= 7.4.2 - Cross-Site Scripting

medium

The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.

CVSS:
6.1
Affected:
up to 7.4.3
Fixed in:
7.4.3
Disclosed:
Nov 22, 2017

CVE-2017-18519 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database