What is CVE-2026-14524?
This vulnerability in the ProSolution WP Client plugin for WordPress (versions up to and including 2.0.8) allows unauthenticated attackers to delete arbitrary files on the server due to insufficient file path validation in the `proSol_fileDeleteProcess` function. Updating to the latest patched version is strongly recommended.
Azərbaycanca: Bu boşluq WordPress üçün ProSolution WP Client plaginində zəiflikdir. 2.0.8-ə qədər bütün versiyalarda təsdiqlənməmiş autentifikasiyasız hücumçulara `proSol_fileDeleteProcess` funksiyasındakı qeyri-kafi fayl yolu validasiyası səbəbilə serverdə ixtiyari faylları silməyə imkan verir. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which plugin is affected by CVE-2026-14524?
This vulnerability affects all versions of the ProSolution WP Client plugin for WordPress up to and including 2.0.8.
What can an attacker exploiting CVE-2026-14524 do?
An unauthenticated attacker can delete arbitrary files on the server due to insufficient file path validation in the `proSol_fileDeleteProcess` function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.