Executive brief
WP Customer Area is a WordPress plugin used to manage private content and file sharing between a site and its customers. A security flaw allows users with basic contributor permissions to embed malicious scripts into pages. These scripts execute automatically when other users, including administrators, visit the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'type' attribute of the `customer-area-protected-content` shortcode. An authenticated attacker with Contributor-level access or higher can exploit this by injecting arbitrary web scripts into a page via the shortcode. Because the script is stored on the server, it executes in the browser of any user who views the compromised page. This vulnerability was addressed in version 8.3.6.
Affected products
- Aguila Technologies WP Customer Area <= 8.3.5
Timeline
- 2026-07-06: patched: Version 8.3.6 released to fix the vulnerability.
- 2026-07-14: disclosed: Public disclosure of CVE-2026-7640.
References
- https://plugins.trac.wordpress.org/browser/customer-area/tags/8.3.4/src/php/core-addons/shortcodes/shortcodes/protected-content-shortcode.class.php
- https://plugins.trac.wordpress.org/browser/customer-area/tags/8.3.6/src/php/core-addons/shortcodes/shortcodes/protected-content-shortcode.class.php
- https://plugins.trac.wordpress.org/browser/customer-area/trunk/src/php/core-addons/shortcodes/shortcodes/protected-content-shortcode.class.php
- https://wordpress.org/plugins/customer-area
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c6f96cec-ddcb-45b2-a28c-b4e7b6f5c719?source=cve