← WordPress Vulnerabilities
WordPress security by component

ProSolution WP Client

ProSolution WP Client (prosolution-wp-client) is a WordPress plugin with 10 published CVE records in this archive. The latest tracked vulnerability was published Aug 19, 2026; the highest published CVSS base score is 9.8.

Plugin slug: prosolution-wp-client

CVE-2026-19056: ProSolution WP Client admin-page attributes permit reflected XSS

ProSolution WP Client before 2.0.11 reflects an attacker-controlled parameter into an HTML attribute on an administrative page without adequate sanitization or escaping. An unauthenticated attacker can induce a logged-in administrator to submit a crafted request, causing script to execute in that administrator's browser under the site origin.

PublishedAug 19, 2026
Known safe version2.0.11
Published vulnerabilities for prosolution-wp-client
Safe version
Aug 19, 2026 CVE-2026-19056
ProSolution WP Client admin-page attributes permit reflected XSS
ProSolution WP Client before 2.0.11 reflects an attacker-controlled parameter into an HTML attribute on an administrative page without adequate sanitization or escaping. An unauthenticated attacker can induce a logged-in administrator to submit a crafted request, causing script to execute in that administrator's browser under the site origin.
2.0.11
CVE7.1
NVDPending
Aug 19, 2026 CVE-2026-19055
ProSolution WP Client public-page attributes permit reflected XSS
ProSolution WP Client before 2.0.11 reflects several attacker-controlled parameters into HTML attributes on public pages without adequate sanitization or escaping. An unauthenticated attacker can direct any visitor, including an authenticated administrator, to a crafted request that executes script under the site's origin.
2.0.11
CVE7.1
NVDPending
Aug 16, 2026 CVE-2026-16098
ProSolution public upload filename mismatch permits remote code execution
ProSolution WP Client through 2.0.10 exposes proSol_handleFileUpload to visitors on pages rendering its job-portal shortcode because the required nonce is published by wp_localize_script. An attacker-controlled Content-Disposition filename overrides the allowlisted multipart filename before the file is written, while the later extension check does not remove the already-saved file. An unauthenticated attacker can therefore place a potentially executable file and obtain remote code execution where the upload location executes PHP. The precise AJAX action and saved path are not disclosed.
See mitigation notes
CVE9.8
NVDPending
Aug 16, 2026 CVE-2026-14524
ProSolution frontend session poisoning permits arbitrary file deletion
ProSolution WP Client through 2.0.8 exposes the frontend nonce needed by proSol_fileUploadModalProcess and proSol_fileDeleteProcess. An unauthenticated attacker first uses the upload-modal handler to place a traversal path into their session, then supplies that session key as filename to proSol_fileDeleteProcess, which lacks adequate path validation. This permits deletion of arbitrary server files and can lead to code execution when a critical file such as wp-config.php is removed. The public.
2.0.9
CVE9.1
NVDPending
Aug 12, 2026 CVE-2026-19052
ProSolution WP Client lets Subscribers run administrative actions
ProSolution WP Client before 2.0.9 exposes the authenticated AJAX actions proSol_ajaxTablesync and proSol_ajaxClearlog without capability checks, while publishing their prosolwpclient nonce on the public front end. A Subscriber can submit table, synctype and batch to trigger administrative data synchronization or cleartype to clear activity records through proSol_clearLog(). The synchronized datasets and clear-log scope depend on configuration.
2.0.9
CVE4.3
NVDPending
Aug 12, 2026 CVE-2026-19050
ProSolution WP Client gives Subscribers a flexible SSRF primitive
ProSolution WP Client before 2.0.9 exposes the proSol_url_validate AJAX action without a capability or nonce check. A Subscriber controls urlval, userval and passval; the plugin creates a WorkExpertAPI Authorization header and uses wp_remote_get() to request urlval plus the fixed /go/api/system/list/maritalstatus path. This can target loopback, private, link-local and cloud-metadata hosts. The inspected code fixes the method to GET and sends no body; the response and exfiltration behavior are not disclosed.
2.0.9
CVE6.4
NVDPending
Aug 10, 2026 CVE-2026-19053
ProSolution WP Client unauthenticated blind SQL injection
ProSolution WP Client before 2.0.6 places the unauthenticated visitor-controlled jobID parameter into a SQL statement without sufficient sanitization or escaping, enabling blind SQL injection.
2.0.6
CVE9.1
NVDPending
Aug 10, 2026 CVE-2026-19049
ProSolution WP Client cookie injection exposes and deletes stored data
ProSolution WP Client before 2.0.9 processes the client-controlled removesite cookie on every request without authentication or a capability check and uses its unsanitized value in SQL queries. An unauthenticated attacker can read arbitrary database data and delete records stored by the plugin.
2.0.9
CVE8.6
NVDPending
May 20, 2026 CVE-2026-6555
ProSolution WP Client: Dangerous file upload
ProSolution WP Client is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 2.0.0.
See mitigation notes
CVE9.8
NVDPending
Apr 08, 2026 CVE-2026-2942
ProSolution WP Client: Dangerous file upload
ProSolution WP Client is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 1.9.9.
See mitigation notes
CVE9.8
NVDPending