Known vulnerabilities in WP Customer Area
WP Customer Area is a modular all-in-one solution to manage private content with WordPress.
7Reported vulnerabilities
8.8Highest CVSS score
8.3.6Latest version
10,000+Active installs
What to do now
Update WP Customer Area to 8.3.6 or later.
6 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-3464 | High | 1.0% | 0 to 8.3.4 (inclusive) | 8.3.5 |
April 17, 2026 |
| CVE-2025-60201 | High | 0.4% | Before 8.3.4 | 8.3.4 |
July 21, 2025 |
| CVE-2026-7640 | Medium | 0.3% | 0 to 8.3.5 (inclusive) | 8.3.6 |
July 14, 2026 |
| CVE-2017-18519 | Medium | 0.9% | Before 7.4.3 | 7.4.3 |
August 20, 2019 |
| CVE-2024-0665 | Medium | 0.5% | Before 8.2.3 | 8.2.3 |
January 24, 2024 |
| CVE-2026-42661 | Medium | 0.4% | 8.3.4 and earlier | 8.3.5 |
May 1, 2026 |
| CVE-2025-49982 | Medium | 0.2% | 8.2.5 and earlier | — | June 19, 2025 |