Known vulnerabilities in Client Portal – Private user pages and login
WordPress Client Portal Plugin that creates private pages for all users that only an administrator can edit.
3Reported vulnerabilities
6.5Highest CVSS score
1.2.2Latest version
3,000+Active installs
What to do now
Update Client Portal – Private user pages and login to 1.2.2 or later.
3 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-25003 | Medium | 0.2% | 1.2.1 and earlier | 1.2.2 |
January 16, 2026 |
| CVE-2023-25968 | Medium | 0.3% | 1.1.8 and earlier | 1.1.9 |
February 22, 2023 |
| WF-c3319993-6f2c-425d-8cb2-ab26f7a52139 | Medium | — | 1.1.8 and earlier | 1.1.9 |
February 21, 2023 |