Junglewise Threat Intelligence

CVE-2026-42661: WP Customer Area path traversal in custom roles

CVE-2026-42661 · Severity: high · CVSS 8.8 · Published 2026-06-15

Executive brief

WP Customer Area is a WordPress plugin used to manage private content and files for clients. A security flaw allows users with specific custom roles to access or manipulate files outside of their intended directory. This could lead to the exposure of sensitive system files or the unauthorized modification of website data.

Technical details

A path traversal vulnerability (CWE-35) exists in the WP Customer Area plugin for WordPress in versions up to and including 8.3.4. The flaw is rooted in insufficient validation of user-supplied input used to construct file paths, specifically affecting components accessible to users with certain custom roles. An authenticated attacker with low-level privileges can exploit this by using 'dot-dot-slash' (../) sequences to navigate the server's file system. This can result in the disclosure of sensitive files, unauthorized data modification, or full system compromise depending on the server configuration. The issue is resolved in version 8.3.5.

Affected products

  • WP Customer Area WP Customer Area <= 8.3.4

Timeline

  • 2026-04-01: disclosed: Reported by iamlooper
  • 2026-05-01: advisory: Patchstack published advisory
  • 2026-06-15: disclosed: NVD publication date
  • 2026-05-01: patched: Version 8.3.5 released

References