Junglewise Threat Intelligence

CVE-2026-40724: Client Portal Ltd. Client Portal (Pro) Arbitrary File Download

CVE-2026-40724 · Severity: medium · CVSS 6.5 · Published 2026-06-17

Executive brief

The Client Portal (Pro) plugin for WordPress, which provides a secure area for clients to access files and project information, contains a security flaw. An attacker with basic client-level access can exploit this vulnerability to download sensitive files from the server that they should not have access to. This could lead to the exposure of configuration files, database credentials, or other private site data.

Technical details

A path traversal vulnerability (CWE-22) exists in the Client Portal (Pro) plugin for WordPress. The flaw allows an authenticated user with 'CP Client' privileges to bypass directory restrictions and download arbitrary files from the server. This is likely due to insufficient validation of user-supplied input used in file download operations. An attacker can leverage this to retrieve sensitive system files, such as wp-config.php, potentially leading to full site compromise. The issue is resolved in version 5.6.3.

Affected products

  • Client Portal Ltd. Client Portal (Pro) <= 5.6.2

Timeline

  • 2025-12-21: other: Vulnerability reported by researcher
  • 2026-04-16: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: CVE published to NVD
  • 2026-06-17: patched: Patch confirmed available in version 5.6.3

References