Description
WP Customer Area is a modular all-in-one solution to manage private content with WordPress. Sharing files/pages with
one or multiple users is one of the main feature provided by our easy-to-use plugin. Give it a try!
Current features
- Secure customer area, accessible to logged-in users
- Private pages, that can be assigned to a particular user and will get listed in its customer area
- Private files, that can be assigned to a particular user and will get listed in its customer area
- Customize the plugin appearance using your own themes and templates
Extensions and themes are now available!
Invoicing, Conversations, Advanced ownership, Projects, and much more!
WP Customer Area is available for free and should cover the needs of most users. If you want to encourage us to actively
maintain it, or if you need a particular feature not included in the basic plugin, you can buy our premium extensions
from our online shop
Special thanks
To Steve Steiner for his intensive testing on the plugin, his bug reports and support.
To the translators who send us their translations:
- Catalan by Amanda Fontana
- Dutch by Paul Willems and Peter Massar
- English by Foobar Studio
- French by Foobar Studio
- German by Benjamin Oechsler
- Hungarian by Jagri István
- Spanish by Ulises and e-rgonomy
- Brazilian Portuguese by Ricardo Silva and Marcos Meyer Hollerweger
- Italian by Andrea Starz and Antonio Cicirelli
- Swedish by Patric Liljestrand
- Turkish by Mehmet Hakan
If you translate the plugin to your language, feel free to send us the translation files, we will include them and give
you the credit for it on this page.
Screenshots















Installation
See our Getting started documentation.
FAQ
-
Getting help / documentation / support / demo / …
-
You have all the information on the plugin website
-
That feature is missing, will you implement it?
-
Open a new topic on the plugin’s support forum, I will consider every feature request and all ideas are welcome.
-
I implemented something, could you integrate it in the plugin?
-
Contributions are welcome. The plugin has a Gitlab repository for contributors
feel free to fork the project and send us pull requests!
Reviews
Contributors & Developers
“WP Customer Area” is open source software. The following people have contributed to this plugin.
Contributors“WP Customer Area” has been translated into 7 locales. Thank you to the translators for their contributions.
Translate “WP Customer Area” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
8.3.6 (2026/07/06)
- Security: fixed a stored XSS vulnerability via the unescaped
typeattribute of the[customer-area-protected-content]shortcode (CVE-2026-7640).
8.3.5 (2026/04/16)
- Security: fixed multiple privilege/path validation issues in file and editor-image handlers to prevent unauthorized post updates, path traversal, and arbitrary image deletion.
8.3.4 (2026/02/05)
- Fix: Licenses validation and error messages
8.3.3 (2026/01/15)
- Fix: Licenses check stuck on activation/validation
8.3.2 (2025/12/12)
- Fix: Compatibility with WP 6.9
8.3.1 (2025/11/28)
- Security: Fixed Local File Inclusion (LFI) vulnerability in file download feature
- Security: Added strict path validation to prevent directory traversal attacks
- Security: Improved file access controls and sanitization
8.2.7 (2025/09/16)
- Fix: Security update on license activation
8.2.6 (2025/09/03)
- Fix: Security update ACL
8.2.5 (2025/01/14)
- Fix: Security update
8.2.4 (2024/06/19)
- Fix: Roles allowed to manage any attachment were not allowed to attach files to other users’ posts
- Fix: Minor graphic issue with the frontend editor
- Fix: PHP 8.3 Warning in settings page
** Add-on Changes **
- ** Authentication Forms ** – Fix: Login form issue
- ** Design Extras ** – Fix: Minor graphic issue with the frontend editor
8.2.3 (2024/01/23)
- Fix: Update some translation strings
- Tweak: Update languages files
- Tweak: Payment notes can now be multiline
** Add-on Changes **
- ** Bulk Import ** – Fix: Bug preventing some capabilities to show in the settings panel
- ** Content Expiry ** – Fix: Option “Set a post expiry” was not showing up in Capabilities page if Front-Office add-on was deactivated
- ** Projects ** – Fix: User role was able to list any project in the backend if he had the “Edit projects” capability
- ** Projects ** – Tweak: Added a “List all projects” option in Capabilities page to allow some roles to list all projects on the system
8.2.2 (2024/01/19)
- Fix: Enhance some ownership and security checks
8.2.1 (2023/12/29)
- Fix: Code review
- Fix: Authored posts were not showing up on the admin side even when ‘hide authored posts’ option was unchecked
- Fix: Archive widget was not taking in account authored posts when ‘hide authored posts’ option was unchecked
- Fix: Recent posts widgets not showing up without previously selecting a category
** Add-on Changes **
- ** FTP PMass Import ** – Fix: Bug preventing some capabilities to show in the settings panel
- ** Invoicing ** – Fix: Addresses’ fields
8.2.0 (2023/07/21)
- New: Support for new Bulk Import add-on
- New: Support for new Elementor Compatibility add-on
- New: Allow admin listing to be sorted by title and date
- Tweak: Few design and CSS tweaks (menu, sidebars, content styling, etc…)
- Tweak: Enhanced compatibility with components from Elementor included into private contents
- Fix: Compatibility issue with Twenty Thirteen theme
- Fix: Authored contents were missing from widget listings when Content Expiry add-on was enabled
- Fix: Select boxes styles missing in admin profile page
- Fix: Textarea autogrow was not working anymore (for invoices and account)
- Fix: Prevent add-ons to stop working in case their folder are renamed
** Add-on changes **
- ** All add-ons ** – Fix: Prevent add-ons to stop working in case their folder are renamed
- ** All add-ons ** – Tweak: Update languages files and fr_FR translations
- ** Design Extras ** – New: Support for new styles from WP Customer Area 8.2.0
- ** DIVI compatibility ** – New: Add-on is now disabled if current theme is not running Divi as current or parent theme
- ** Content Expiry ** – New: Compatibility with Front-Office Publishing add-on (expiration dates can now be set from the frontend)
- ** Content Expiry ** – New: Added new permission to allow roles to set a post expiry from the frontend
- ** Content Expiry ** – New: Add expired badge on dashboard and collections view if post is expired
- ** Content Expiry ** – Fix: Fixed some meta_queries that were slowing down content listings page loading in some cases
- ** Content Expiry ** – Fix: The author of an expired post will now still be able to view it
- ** Content Expiry ** – Tweak: Update tile validation status on single content posts in case post is expired
- ** Conversations ** – New: Add emojis compatibility in conversations replies
- ** Conversations ** – New: Alternate colors and replies position depending on currently connected user
- ** Conversations ** – Tweak: Add editor replies default styles (such as lists, links, etc..)
- ** Conversations ** – Fix: Height sizing issue that was making conversations replies overlapping the site’s footer
- ** Conversations ** – Fix: Wrong left/right position for replies in some cases
- ** Front-Office Publishing ** – Tweak: Allow files upload dialog box to select multiple files if Enhanced Files add-on is active
- ** Invoicing ** – Fix: invoicing vat fields were not properly loading data on the admin edit post screen
- ** Projects ** – Fix: Removed compatibility with the content expiry add-on. Post expiration should now be set into attached posts
- ** Protect Post Types ** – Fix: Post Owners were not showing up in the “Assigned to” column of the protected post types listing, in the backend
- ** Tasks ** – Fix: Compatibility with frontend tasks edit form and the TwentyThirteen theme
- ** Search ** – Fix: Authored contents were missing from search when Content Expiry add-on was enabled
8.1.6 (2022/02/21)
- New: Frontend rich-editor options and translatable strings using standard WP translation system (filter ‘cuar/core/js-richEditor’)
- New: Copying/pasting HTML to the editor is now allowed but tags are all filtered out by default (allowed tags are customizable through filter ‘cuar/core/js-richEditor’)
- New: Button to style the Ul and Ol lists in the toolbar of the frontend rich-editor
- New: Button to add Embed shortcode from external media sites (youtube, soundcloud, vimeo, etc.)
- Fix: Authored contents were missing from listings when Content Expiry add-on was enabled
- Fix: New lines in the frontend rich-editor are now div wrapped
- Fix: Not properly working Ul and Ol lists of the frontend rich-editor
- Fix: Some 404 links to WPCA’s site
- Tweak: Update languages
** Add-on changes **
- ** Design Extras ** – New: Support for new styles from WP Customer Area 8.1.6
- ** Owner Restrictions ** – New: Add new user restriction “Any member of the groups where the author is a member”
- ** Authentication Forms ** – Fix: “Invalid Key” error was showing up in some cases when using the Lost-Password form
- ** Unread Documents ** – Fix: Do not mark post as “updated” for a user that updated its own post
- ** FTP Mass Import ** – Fix: Option “Import all the selected files within the same private post” not working in some cases
8.1.5 (2022/01/24)
- Tweak: All pages of the private area will now get the same min-height (editable with filter cuar/core/page/sidebar-attributes)
** Add-on changes **
- ** Conversations ** – New: Add emojis compatibility in conversations replies
- ** Conversations ** – Fix: Height sizing issue that was making conversations replies overlapping the site’s footer
- ** Design Extras ** – New: Support for new styles from WP Customer Area 8.1.5
8.1.4 (2022/01/14)
- Fix: Security issue
- Fix: PHP error when viewing a PDF Invoice
8.1.3 (2022/11/23)
- New: Support for WP 6.1.x
- New: Add new category tile for private pages and files in single content pages
- Fix: Add-ons were performing update checks on every page loads
- Fix: Remove Project Add button sub-item (Attach new private file) if current user does not have required capabilities
- Fix: Remove Project Add button sub-item (Attach new private page) if current user does not have required capabilities
- Fix: Missing permalinks for private posts and private categories in admin area
- Fix: Monthly archives link in single content pages
- Tweak: Reduced width for customer-account-edit page based on cuar/private-content/view/max-width-for-forms
- Tweak: Reduced width for customer-dashboard page based on cuar/private-content/view/max-width-for-inner-pages
- Tweak: Languages files updated
** Add-on changes **
- ** All ** – New: Compatibility with WordPress 6.1.x
- ** All ** – Languages files updated
- ** ACF Integration ** – New: Support for ACF Version 5.12.x
- ** ACF Integration ** – New: Support for ACF Version 6.0.x
- ** Design Extras ** – New: Support for new styles from WP Customer Area 8.1.3
- ** FTP Mass Import ** – Fix: Publish automatically checkbox not properly working
- ** FTP Mass Import ** – Fix: Files not deleted in some cases
- ** FTP Mass Import ** – Fix: Files wrongly published within a same private post in some cases
- ** FTP Mass Import ** – Fix: Disable Option where Enhanced Files add-on is required, if it is not activated
- ** Projects ** – Fix: Remove Project Add button (or sub-items) if current user does not have required capabilities
- ** Projects ** – Fix: Missing permalinks for private posts and private categories in admin area
- ** Tasks ** – Fix: Missing permalinks for private posts and private categories in admin area
- ** Tasks ** – Fix: Monthly archives link in single content pages
