PT-2026-78300 · WordPress · Prosolution Wp Client
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
ProSolution WP Client versions prior to 2.0.11
Description
Insufficient sanitization and escaping of several parameters before they are reflected into HTML attributes on public pages allow for reflected Cross-Site Scripting (XSS). This issue can be triggered against any visitor, including logged-in administrators. Cross-Site Scripting is a technique where malicious scripts are injected into trusted websites.
Recommendations
Update ProSolution WP Client to version 2.0.11 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prosolution Wp Client