If you allow customers to publish on subdomain, let's say example.quickpublisher.online, the customer site will receive all cookies from the top domain quickpublisher.online (read: user sessions), this allows to trivially steal user accounts from other customers visiting the site, then take over their resources or credit cards (assuming there is some payments attached to the account).
TLDR; If you're a customer, go shutdown your account quick before it's stolen. This product is a security disaster that should never have been shipped like that.