What is CVE-2026-19056?
This vulnerability affects the ProSolution WP Client WordPress plugin before version 2.0.11, where a parameter on an administrative page is not sanitized and escaped, leading to reflected Cross-Site Scripting (XSS). It executes in an administrator's session when they are tricked into submitting a crafted request, potentially compromising the site. Upgrading to the latest plugin version is recommended.
Azərbaycanca: Bu zəiflik ProSolution WP Client WordPress plugininin 2.0.11-dən əvvəlki versiyalarında administrativ səhifədəki parametrin düzgün təmizlənməməsi və qaçış edilməməsi səbəbindən baş verir. Administratorun xüsusi hazırlanmış sorğuya məruz qalması nəticəsində reflected Cross-Site Scripting (XSS) hücumuna yol açır, bu da administrator sessiyasında icra oluna bilər. Pluginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Which plugin is affected by CVE-2026-19056 and what causes it?
This vulnerability affects the ProSolution WP Client WordPress plugin. It occurs because a parameter on an administrative page is not properly sanitized and escaped in versions before 2.0.11.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.