CVE-2026-19056: ProSolution WP Client < 2.0.11 - Reflected XSS via 'page' Parameter
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Administrators using a vulnerable version of the ProSolution WP Client plugin are exposed if they can be induced to submit a crafted request to the affected administrative page. The XSS executes in the administrator's authenticated session.
What must an attacker do to exploit this issue?
The attacker needs to induce an administrator to submit a crafted request containing a malicious value in the page parameter. The issue is reflected in an HTML attribute on an administrative page.
Which versions are affected?
ProSolution WP Client versions before 2.0.11 are affected. Updating to version 2.0.11 or later addresses the affected version range.