WordPress security by component
ProSolution WP Client
ProSolution WP Client (prosolution-wp-client) is a WordPress plugin with 10 published CVE records in this archive. The latest tracked vulnerability was published Aug 19, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
prosolution-wp-clientLatest vulnerability
CVE-2026-19056: ProSolution WP Client admin-page attributes permit reflected XSS
ProSolution WP Client before 2.0.11 reflects an attacker-controlled parameter into an HTML attribute on an administrative page without adequate sanitization or escaping. An unauthenticated attacker can induce a logged-in administrator to submit a crafted request, causing script to execute in that administrator's browser under the site origin.
| Safe version |
|
||
|---|---|---|---|
| Aug 19, 2026 |
CVE-2026-19056
ProSolution WP Client admin-page attributes permit reflected XSS
ProSolution WP Client before 2.0.11 reflects an attacker-controlled parameter into an HTML attribute on an administrative page without adequate sanitization or escaping. An unauthenticated attacker can induce a logged-in administrator to submit a crafted request, causing script to execute in that administrator's browser under the site origin.
|
2.0.11 |
CVE7.1
NVDPending
|
| Aug 19, 2026 |
CVE-2026-19055
ProSolution WP Client public-page attributes permit reflected XSS
ProSolution WP Client before 2.0.11 reflects several attacker-controlled parameters into HTML attributes on public pages without adequate sanitization or escaping. An unauthenticated attacker can direct any visitor, including an authenticated administrator, to a crafted request that executes script under the site's origin.
|
2.0.11 |
CVE7.1
NVDPending
|
| Aug 16, 2026 |
CVE-2026-16098
ProSolution public upload filename mismatch permits remote code execution
ProSolution WP Client through 2.0.10 exposes proSol_handleFileUpload to visitors on pages rendering its job-portal shortcode because the required nonce is published by wp_localize_script. An attacker-controlled Content-Disposition filename overrides the allowlisted multipart filename before the file is written, while the later extension check does not remove the already-saved file. An unauthenticated attacker can therefore place a potentially executable file and obtain remote code execution where the upload location executes PHP. The precise AJAX action and saved path are not disclosed.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Aug 16, 2026 |
CVE-2026-14524
ProSolution frontend session poisoning permits arbitrary file deletion
ProSolution WP Client through 2.0.8 exposes the frontend nonce needed by proSol_fileUploadModalProcess and proSol_fileDeleteProcess. An unauthenticated attacker first uses the upload-modal handler to place a traversal path into their session, then supplies that session key as filename to proSol_fileDeleteProcess, which lacks adequate path validation. This permits deletion of arbitrary server files and can lead to code execution when a critical file such as wp-config.php is removed. The public.
|
2.0.9 |
CVE9.1
NVDPending
|
| Aug 12, 2026 |
CVE-2026-19052
ProSolution WP Client lets Subscribers run administrative actions
ProSolution WP Client before 2.0.9 exposes the authenticated AJAX actions proSol_ajaxTablesync and proSol_ajaxClearlog without capability checks, while publishing their prosolwpclient nonce on the public front end. A Subscriber can submit table, synctype and batch to trigger administrative data synchronization or cleartype to clear activity records through proSol_clearLog(). The synchronized datasets and clear-log scope depend on configuration.
|
2.0.9 |
CVE4.3
NVDPending
|
| Aug 12, 2026 |
CVE-2026-19050
ProSolution WP Client gives Subscribers a flexible SSRF primitive
ProSolution WP Client before 2.0.9 exposes the proSol_url_validate AJAX action without a capability or nonce check. A Subscriber controls urlval, userval and passval; the plugin creates a WorkExpertAPI Authorization header and uses wp_remote_get() to request urlval plus the fixed /go/api/system/list/maritalstatus path. This can target loopback, private, link-local and cloud-metadata hosts. The inspected code fixes the method to GET and sends no body; the response and exfiltration behavior are not disclosed.
|
2.0.9 |
CVE6.4
NVDPending
|
| Aug 10, 2026 |
CVE-2026-19053
ProSolution WP Client unauthenticated blind SQL injection
ProSolution WP Client before 2.0.6 places the unauthenticated visitor-controlled jobID parameter into a SQL statement without sufficient sanitization or escaping, enabling blind SQL injection.
|
2.0.6 |
CVE9.1
NVDPending
|
| Aug 10, 2026 |
CVE-2026-19049
ProSolution WP Client cookie injection exposes and deletes stored data
ProSolution WP Client before 2.0.9 processes the client-controlled removesite cookie on every request without authentication or a capability check and uses its unsanitized value in SQL queries. An unauthenticated attacker can read arbitrary database data and delete records stored by the plugin.
|
2.0.9 |
CVE8.6
NVDPending
|
| May 20, 2026 |
CVE-2026-6555
ProSolution WP Client: Dangerous file upload
ProSolution WP Client is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 2.0.0.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Apr 08, 2026 |
CVE-2026-2942
ProSolution WP Client: Dangerous file upload
ProSolution WP Client is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 1.9.9.
|
See mitigation notes |
CVE9.8
NVDPending
|