
CVE-2026-3464 The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_attach_file' function … https://www.cve.org/CVERecord?id=CVE-2026-3464
Post summary
The post discloses that CVE-2026-3464 allows arbitrary file read and deletion in the WP Customer Area WordPress plugin due to flawed file path validation in the ajax_attach_file function.


