The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores.
CVE-2026-19049
NONE
EPSS 0.21%
Updated Aug 10, 2026
WordPress
CVE Details
CVE ID
CVE-2026-19049
Published Date
Aug 10, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.21%
Likelihood of exploitation in next 30 days
Percentile:
10.9th percentile (higher than 10.9% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory