Unauthorized Access in ProSolution WP Client Plugin for WordPress
CVE-2026-19052
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 12 August 2026
Badges
What is CVE-2026-19052?
The ProSolution WP Client plugin for WordPress, prior to version 2.0.9, suffers from a serious security flaw due to inadequate checks on administrative AJAX actions. This oversight permits any authenticated user, including those with limited roles such as subscribers, to invoke administrative data synchronization tasks. Additionally, the nonce, which is integral for validating actions, is publicly accessible on the frontend. This makes it feasible for unauthorized users to clear activity records of the plugin, potentially compromising the integrity and privacy of sensitive data.
Affected Version(s)
ProSolution WP Client 0 < 2.0.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.