What is CVE-2026-19052?
This CVE is a privilege escalation vulnerability in the "ProSolution WP Client" WordPress plugin before version 2.0.9. The plugin lacks capability checks on administrative AJAX actions and exposes the required nonce on the public frontend, allowing any authenticated user (like a subscriber) to trigger administrative data synchronization. Affected sites should immediately update the plugin to the latest version.
Azərbaycanca: Bu CVE, "ProSolution WP Client" WordPress plugin-in 2.0.9-dan əvvəlki versiyalarında aşkar edilmiş imtiyaz yüksəltmə zəifliyidir. Plugin, admin AJAX əməliyyatları üçün lazımi icazə yoxlaması (capability check) aparmır və tələb olunan nonce dəyərini ictimai frontend-də yayımlayır, bu da sadə bir abunəçi kimi autentifikasiya olunmuş istənilən istifadəçiyə inzibati məlumat sinxronizasiyasını işə salmağa imkan verir. Təsirə məruz qalan saytlar dərhal plugin-i son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the 'ProSolution WP Client' plugin are affected by CVE-2026-19052?
This vulnerability exists in versions of the plugin before 2.0.9.
Is authentication required to exploit CVE-2026-19052?
Yes, any user authenticated as a subscriber is sufficient to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.