SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-19056

HIGH · CVSS 7.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The ProSolution WP Client plugin for WordPress versions prior to 2.0.11 is vulnerable to reflected Cross-Site Scripting due to improper sanitization and escaping of a parameter in an administrative page's HTML attribute. This vulnerability allows an attacker to execute malicious scripts in the context of an administrator's session, potentially compromising the site. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-19056
Severity
HIGH
CVSS
7.1
EPSS
0.18%
WordPress

Original NVD Description

The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request.