AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19049

HIGH · CVSS 8.6 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The ProSolution WP Client plugin for WordPress prior to version 2.0.9 is vulnerable due to inadequate sanitization of cookie values used in SQL queries, enabling unauthenticated users to access and manipulate database records. This flaw allows attackers to read sensitive data and delete records without any authentication or capability checks. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized data exposure and potential data loss.

CVE
CVE-2026-19049
Severity
HIGH
CVSS
8.6
EPSS
0.30%
WordPress

Original NVD Description

The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores.