AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19050

MEDIUM · CVSS 6.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The ProSolution WP Client plugin for WordPress versions prior to 2.0.9 is vulnerable due to insufficient validation of user-supplied URLs and a lack of capability checks, enabling authenticated users to initiate arbitrary server-side HTTP requests. This flaw could lead to unauthorized access to internal services and data, potentially allowing attackers to manipulate requests with custom methods and payloads. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-19050
Severity
MEDIUM
CVSS
6.4
EPSS
0.14%
WordPress

Original NVD Description

The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the site issue arbitrary requests to internal hosts and services, including requests with an attacker-chosen method, headers and body.