PT-2026-69379 · WordPress · Prosolution Wp Client

CVE-2026-19053

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ProSolution WP Client versions prior to 2.0.6
Description Unauthenticated visitors can trigger a blind SQL injection, a technique used to extract information from a database by observing the application's response to specific queries. The issue occurs because the plugin fails to sanitize and escape the jobID parameter before incorporating it into a SQL statement.
Recommendations Update ProSolution WP Client to version 2.0.6 or later. Avoid using the jobID parameter until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19053

Affected Products

Prosolution Wp Client