CVE-2026-19055Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-19: 2Technical Details · 2026-08-19: 208-19
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19055 The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pag… https://www.cve.org/CVERecord?id=CVE-2026-19055 ----- Traducción: CVE-2026-19055 El … https://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑19055, detailing a missing input sanitisation in the ProSolution WP Client WordPress plugin that could lead to reflective XSS, but does not provide a PoC, exploit, patch, or mention active exploitation.

    0000072
    100 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-19055 The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pag… https://www.cve.org/CVERecord?id=CVE-2026-19055

    Post summary

    The text reports that the ProSolution WP Client plugin fails to sanitize certain parameters before reflecting them into HTML attributes, implying a potential XSS vulnerability, but does not provide evidence of exploitation, a PoC, or a patch.

    000001.1K
    58.0K followersView on X

Explore more