CVE-2026-19055
Deferred Deferred - Pending Action

Reflected Cross-Site Scripting in ProSolution WP Client WordPress Plugin

Vulnerability report for CVE-2026-19055, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-26

Assigner: WPScan

Description

The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-26
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
prosolution wp_client to 2.0.11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a reflected Cross-Site Scripting (XSS) vulnerability in the ProSolution WP Client WordPress plugin before version 2.0.11. It occurs because the plugin does not properly sanitize and escape certain parameters before reflecting them into HTML attributes on public pages. This allows attackers to inject malicious scripts that execute when visitors, including logged-in administrators, access the affected pages.

Detection Guidance

To detect this vulnerability, check the installed version of the ProSolution WP Client plugin. If it is below 2.0.11, the system is vulnerable. You can verify the version via the WordPress admin panel under Plugins or by inspecting the plugin files on the server.

Impact Analysis

An attacker could exploit this vulnerability to run malicious scripts in the browsers of anyone visiting the affected site, including administrators. This could lead to theft of session cookies, account takeover, or unauthorized actions performed on behalf of the user. The impact includes potential data breaches or compromise of the WordPress site.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by enabling unauthorized access to personal or sensitive data. If exploited, it may result in data breaches that violate these regulations, potentially leading to legal penalties, fines, or reputational damage for organizations handling protected information.

Mitigation Strategies

Immediately update the ProSolution WP Client plugin to version 2.0.11 or later. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Regularly monitor the plugin's official channels for updates and security advisories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19055. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart