AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19053

CRITICAL · CVSS 9.1 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The ProSolution WP Client WordPress plugin prior to version 2.0.6 is vulnerable to a blind SQL injection due to inadequate sanitization and escaping of user-supplied parameters in SQL statements, which can be exploited by unauthenticated users. This vulnerability could allow attackers to manipulate the database, potentially leading to data exposure or corruption. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-19053
Severity
CRITICAL
CVSS
9.1
EPSS
0.24%
WordPress

Original NVD Description

The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection.