WP Customer Area <= 8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'type' Shortcode Attribute
medium
The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `customer-area-protected-content` shortcode in all versions up to, and including, 8.3.5. This is due to insufficient input sanitization and output escaping on the shortcode attribute. This makes it pos...
- CVSS:
- 6.4
- Affected:
- up to 8.3.5
- Fixed in:
- 8.3.6
- Disclosed:
- Jul 13, 2026
CVE-2026-7640 on NVD →
WP Customer Area <= 8.3.4 - Authenticated (Custom+) Path Traversal
medium
The WP Customer Area plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 8.3.4. This makes it possible for authenticated attackers, with Custom-level access and above, to perform actions on files outside of the originally intended directory.
- CVSS:
- 5.3
- Affected:
- up to 8.3.4
- Fixed in:
- 8.3.5
- Disclosed:
- May 1, 2026
CVE-2026-42661 on NVD →
WP Customer Area <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Read/Deletion via ajax_attach_file
high
The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_attach_file' function in all versions up to, and including, 8.3.4. This makes it possible for authenticated attackers with a role that an administrator grants access to (e.g....
- CVSS:
- 8.8
- Affected:
- up to 8.3.4
- Fixed in:
- 8.3.5
- Disclosed:
- Apr 17, 2026
CVE-2026-3464 on NVD →
WP Customer Area [customer-area] <= 8.2.7 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in aguilatechnologies WP Customer Area customer-area allows PHP Local File Inclusion.This issue affects WP Customer Area: from n/a through <= 8.2.7.
- Affected:
- up to 8.2.7
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-60201 on NVD →
Customer Area < 8.3.4 - Unauthenticated Local File Inclusion
high
The Customer Area plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 8.3.4. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access contro...
- CVSS:
- 8.1
- Affected:
- up to 8.3.4
- Fixed in:
- 8.3.4
- Disclosed:
- Jul 21, 2025
CVE-2025-60201 on NVD →
WP Customer Area [customer-area] <= 8.2.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in aguilatechnologies WP Customer Area allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Customer Area: from n/a through 8.2.5.
- Affected:
- up to 8.2.5
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2025
CVE-2025-49982 on NVD →
WP Customer Area <= 8.2.5 - Missing Authorization
medium
The WP Customer Area plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 8.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 8.2.5
- Fix:
- No patched version reported
- Disclosed:
- Jun 19, 2025
CVE-2025-49982 on NVD →
WP Customer Area [customer-area] < 8.2.5
unknown
[en] The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- Affected:
- up to 8.2.5
- Fixed in:
- 8.2.5
- Disclosed:
- Jan 27, 2025
CVE-2024-12436 on NVD →
WP Customer Area [customer-area] < 8.2.5
unknown
[en] The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack
- Affected:
- up to 8.2.5
- Fixed in:
- 8.2.5
- Disclosed:
- Jan 27, 2025
CVE-2024-12280 on NVD →
WP Customer Area <= 8.2.4 - Cross-Site Request Forgery to Event Log Deletion
medium
The WP Customer Area plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.2.4. This is due to missing or incorrect nonce validation on the 'wpca-logs' page. This makes it possible for unauthenticated attackers to delete event logs via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 8.2.4
- Fixed in:
- 8.2.5
- Disclosed:
- Jan 6, 2025
CVE-2024-12280 on NVD →
WP Customer Area <= 8.2.4 - Cross-Site Request Forgery to Bulk Deletion
medium
The WP Customer Area plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.2.4. This is due to missing or incorrect nonce validation on the 'cuar-trash' action. This makes it possible for unauthenticated attackers to delete customer files via a forged request granted t...
- CVSS:
- 4.3
- Affected:
- up to 8.2.4
- Fixed in:
- 8.2.5
- Disclosed:
- Jan 6, 2025
CVE-2024-12436 on NVD →
WP Customer Area [customer-area] < 8.2.3
unknown
[en] The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- Affected:
- up to 8.2.3
- Fixed in:
- 8.2.3
- Disclosed:
- Jan 24, 2024
CVE-2024-0665 on NVD →
WP Customer Area <= 8.2.2 - Reflected Cross-Site Scripting
medium
The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 8.2.2
- Fixed in:
- 8.2.3
- Disclosed:
- Jan 23, 2024
CVE-2024-0665 on NVD →
WP Customer Area [customer-area] < 8.2.1
unknown
[en] The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address.
- Affected:
- up to 8.2.1
- Fixed in:
- 8.2.1
- Disclosed:
- Jan 16, 2024
CVE-2023-6741 on NVD →
WP Customer Area [customer-area] < 8.2.1
unknown
[en] The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address.
- Affected:
- up to 8.2.1
- Fixed in:
- 8.2.1
- Disclosed:
- Jan 16, 2024
CVE-2023-6824 on NVD →
WP Customer Area <= 8.2.1 - Insecure Direct Object Reference to Address Modification
medium
The WP Customer Area plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_address_for_owner function in all versions up to, and including, 8.2.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify address...
- CVSS:
- 4.3
- Affected:
- up to 8.2.0
- Fixed in:
- 8.2.1
- Disclosed:
- Jan 10, 2024
CVE-2023-6741 on NVD →
WP Customer Area <= 8.2.0 - Insecure Direct Object Reference to Account Address Disclosure
medium
The WP Customer Area plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_load_address_from_owner() function in all versions up to, and including, 8.2.0. This makes it possible for authenticated attackers with subscriber-level access and above, to retrieve othe...
- CVSS:
- 4.3
- Affected:
- up to 8.2.0
- Fixed in:
- 8.2.1
- Disclosed:
- Jan 10, 2024
CVE-2023-6824 on NVD →
WP Customer Area [customer-area] < 8.1.4
unknown
[en] The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example.
- Affected:
- up to 8.1.4
- Fixed in:
- 8.1.4
- Disclosed:
- Feb 13, 2023
CVE-2022-4745 on NVD →
WP Customer Area <= 8.1.3 - Cross-Site Request Forgery
high
The WP Customer Area plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.1.3. This is due to missing or incorrect nonce validation on several functions related to file and folder management. This makes it possible for unauthenticated attackers to invoke those functions v...
- CVSS:
- 8.8
- Affected:
- up to 8.1.3
- Fixed in:
- 8.1.4
- Disclosed:
- Jan 17, 2023
CVE-2022-4745 on NVD →
WP Customer Area [customer-area] < 7.4.3
unknown
[en] The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.
- Affected:
- up to 7.4.3
- Fixed in:
- 7.4.3
- Disclosed:
- Aug 20, 2019
CVE-2017-18519 on NVD →
WP Customer Area [customer-area] < 7.4.3
unknown
The value of $_REQUEST[‘page’] parameter is not escaped in the template files - /src/php/core-addons/admin-area/templates/. This allows an attacker to execute a reflected cross site scripting attack. The vulnerability was fixed in version 7.4.3.
- Affected:
- up to 7.4.3
- Fixed in:
- 7.4.3
- Disclosed:
- Nov 27, 2017
WP Customer Area <= 7.4.2 - Cross-Site Scripting
medium
The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.
- CVSS:
- 6.1
- Affected:
- up to 7.4.3
- Fixed in:
- 7.4.3
- Disclosed:
- Nov 22, 2017
CVE-2017-18519 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database