VYPR

Prosolution Wp Client

by WordPress

Source repositories

CVEs (10)

  • CVE-2026-16098CriAug 16, 2026
    risk 0.64cvss 9.8epss 0.01

    The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which…

  • CVE-2026-6555CriMay 20, 2026
    risk 0.64cvss 9.8epss 0.01

    The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files…

  • CVE-2026-14524CriAug 16, 2026
    risk 0.59cvss 9.1epss 0.01

    The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete…

  • CVE-2026-19053CriAug 10, 2026
    risk 0.59cvss 9.1epss 0.00

    The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection.

  • CVE-2026-2942CriApr 8, 2026
    risk 0.57cvss 9.8epss 0.01

    The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload…

  • CVE-2026-19049HigAug 10, 2026
    risk 0.56cvss 8.6epss 0.01

    The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the…

  • CVE-2026-19056HigAug 19, 2026
    risk 0.46cvss 7.1epss 0.00

    The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to…

  • CVE-2026-19055HigAug 19, 2026
    risk 0.46cvss 7.1epss 0.00

    The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in…

  • CVE-2026-19050MedAug 12, 2026
    risk 0.42cvss 6.4epss 0.00

    The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the…

  • CVE-2026-19052MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data…