What is CVE-2026-19055?
The ProSolution WP Client plugin before version 2.0.11 fails to sanitise and escape several parameters, resulting in a Reflected Cross-Site Scripting (XSS) vulnerability. This can be triggered against any visitor, including logged-in administrators. Immediate update to the latest version is recommended.
Azərbaycanca: ProSolution WP Client plaqininin 2.0.11-dən əvvəlki versiyalarında bir neçə parametrdə təmizlənmə (sanitisation) və escape edilməməsi səbəbindən Reflected Cross-Site Scripting (XSS) zəifliyi aşkar edilib. Bu, istənilən ziyarətçiyə, o cümlədən administratora qarşı hücum keçirilməsinə imkan verir. Dərhal plaqini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the ProSolution WP Client plugin are affected by CVE-2026-19055?
This Reflected Cross-Site Scripting (XSS) vulnerability affects versions of the plugin prior to 2.0.11.
What should be done to protect against CVE-2026-19055?
Immediate update to the latest version of the plugin is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.