All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-19052
MEDIUMpublished 2026-08-12 06:21 UTC · 21 hours ago · modified 2026-08-12 13:17 UTC
4.3
CVSS / 10
// description
The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data synchronisation and to clear the ProSolution WP Client WordPress plugin before 2.0.9's activity records.
// weaknesses (CWE)
- CWE-862