The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 07:16
Updated : 2026-08-26 16:30
NVD link : CVE-2026-19049
Mitre link : CVE-2026-19049
CVE.ORG link : CVE-2026-19049
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
