PT-2026-69378 · WordPress · Prosolution Wp Client
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ProSolution WP Client versions prior to 2.0.9
Description
An issue exists where a cookie value is not sanitized before being used in SQL queries. This cookie is processed on every request without authentication or capability checks, allowing unauthenticated users to read arbitrary data from the database and delete records stored by the plugin. The vulnerable component is the
removesite cookie.Recommendations
Update ProSolution WP Client to version 2.0.9 or later.
As a temporary mitigation, restrict or block the use of the
removesite cookie.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prosolution Wp Client