CVE-2026-19049

The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 07:16

Updated : 2026-08-26 16:30


NVD link : CVE-2026-19049

Mitre link : CVE-2026-19049

CVE.ORG link : CVE-2026-19049


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')