WP Customer Area
WP Customer Area has 12 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2026; 11 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 3 high. 2025 was the busiest year with 4 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 3 of the records (25%). Other recurring categories include Cross-Site Scripting, Authorization Bypass Through User-Controlled Key.
11 of the records (92%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
9 independent researchers contributed these findings, most of them (3) reported by Krzysztof Zając. WP Customer Area is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-49982WP Customer Area <= 8.2.5 - Missing Authorization
Read the full analysisVulnerability Records

WP Customer Area
Author
Aguila Technologies
WP Customer Area is a modular all-in-one solution to manage private content with WordPress. Sharing files/pages with one or multiple users is one of the main feature provided by our easy-to-use plugin. Give it a try! Add-ons Git repository for contributors Issue tracker Current features Secure customer area, accessible to logged-in users Private pages, that can be assigned to a particular user and will get listed in its customer area Private files, that can be assigned to a particular user and will get listed in its customer area Customize the plugin appearance using your own themes and templates Extensions and themes are now available! Invoicing, Conversations, Advanced ownership, Projects, and much more! WP Customer Area is available for free and should cover the needs of most users. If you want to encourage us to actively maintain it, or if you need a particular feature not included in the basic plugin, you can buy our premium extensions from our online shop Special thanks To Steve Steiner for his intensive testing on the plugin, his bug reports and support. To the translators who send us their translations: Catalan by Amanda Fontana Dutch by Paul Willems and Peter Massar English by Foobar Studio French by Foobar Studio German by Benjamin Oechsler Hungarian by Jagri István Spanish by Ulises and e-rgonomy Brazilian Portuguese by Ricardo Silva and Marcos Meyer Hollerweger Italian by Andrea Starz and Antonio Cicirelli Swedish by Patric Liljestrand Turkish by Mehmet Hakan If you translate the plugin to your language, feel free to send us the translation files, we will include them and give you the credit for it on this page.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C