Client Portal – Private user pages and login
Client Portal – Private user pages and login has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.5 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (67%). Other recurring categories include Missing Authorization.
Every one of the 3 issues recorded for Client Portal – Private user pages and login has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Client Portal – Private user pages and login is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-25003Client Portal – Private user pages and login <= 1.2.1 - Missing Authorization
Read the full analysisVulnerability Records

Client Portal – Private user pages and login
Author
madalin.ungureanu
The WordPress Client Portal plugin creates private pages for each user. The content for that page is accessible on the frontend only by the owner of the page after he has logged in. The plugin doesn’t offer a login or registration form and it gives you the possibility to use a plugin of your choice. The [client-portal] shortcode can be added to any page and when the logged in user will access that page he will be redirected to its private page. For login and registration of users we recommend the free Profile Builder plugin. You can then use the [wppb-login] shortcode in the same page as the [client-portal] shortcode.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C