What is CVE-2026-19050?
This vulnerability exists in the 'ProSolution WP Client' WordPress plugin before version 2.0.9, allowing any authenticated user, such as a subscriber, to make arbitrary server-side HTTP requests. The flaw occurs because the plugin fails to validate a user-supplied URL and does not check the requester's capability or nonce, leading to a Server-Side Request Forgery (SSRF) issue. To mitigate, immediately update the plugin to version 2.0.9 or later.
Azərbaycanca: Bu boşluq 'ProSolution WP Client' WordPress plagininin 2.0.9-dan əvvəlki versiyalarında aşkar edilib və istənilən autentifikasiya olunmuş istifadəçiyə (məsələn, abunəçi) server tərəfindən ixtiyari HTTP sorğuları göndərməyə imkan verir. Plagin istifadəçi tərəfindən təqdim edilən URL-i yoxlamadığı və sorğu edənin icazəsini təsdiqləmədiyi üçün bu, Server-Side Request Forgery (SSRF) zəifliyinə səbəb olur. Bu problemi aradan qaldırmaq üçün dərhal plagini ən son 2.0.9 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of the 'ProSolution WP Client' plugin are affected by CVE-2026-19050?
This SSRF vulnerability exists in the 'ProSolution WP Client' plugin before version 2.0.9.
Does CVE-2026-19050 require authentication, and what causes the vulnerability?
Yes, any authenticated user (e.g., a subscriber) can exploit this SSRF flaw. The vulnerability occurs because the plugin fails to validate a user-supplied URL and does not check the requester's capability or nonce.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.