Description
The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data synchronisation and to clear the ProSolution WP Client WordPress plugin before 2.0.9's activity records.
Published: 2026-08-12
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ProSolution WP Client WordPress plugin before 2.0.9 fails to verify user capabilities for two administrative AJAX actions—proSol_ajaxTablesync and proSol_ajaxClearlog. Because the nonce used for these calls is exposed on the public front‑end, any authenticated user who can log into the site, including subscribers who normally lack admin privileges, can trigger these actions. This allows the attacker to initiate an administrative data synchronization or to clear the plugin’s activity records, effectively altering data integrity and potentially disrupting normal operation.

Affected Systems

The vulnerable component is the ProSolution WP Client plugin deployed on WordPress sites. All releases prior to 2.0.9 are affected. No specific WordPress versions or hosting environments are singled out; the issue exists wherever this plugin is active.

Risk and Exploitability

The missing capability checks and publicly accessible nonce make the flaw exploitable by a legitimate but low‑privilege user. While the exploit does not provide direct code execution, it enables unauthorized data manipulation, which can be leveraged to obscure auditing trails or to trigger unintended synchronization that may impact data consistency. The EPSS score is < 1%, indicating a low probability of exploitation, and the CVSS score of 4.3 reflects moderate impact. The vulnerability is not listed in the CISA KEV catalog, but the potential impact on data integrity warrants prompt remediation.

Generated by OpenCVE AI on August 13, 2026 at 03:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ProSolution WP Client to version 2.0.9 or later
  • Restrict subscriber role capabilities so that users cannot trigger proSol_ajaxTablesync or proSol_ajaxClearlog
  • If an upgrade is not feasible, remove or secure the endpoint to allow execution only by users with the appropriate capabilities

Generated by OpenCVE AI on August 13, 2026 at 03:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Prosolution
Prosolution prosolution Wp Client
Wordpress
Wordpress wordpress
Vendors & Products Prosolution
Prosolution prosolution Wp Client
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284

Wed, 12 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data synchronisation and to clear the ProSolution WP Client WordPress plugin before 2.0.9's activity records.
Title ProSolution WP Client < 2.0.9 - Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog Calls
References

Subscriptions

Prosolution Prosolution Wp Client
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T12:21:36.326Z

Reserved: 2026-08-06T07:51:06.845Z

Link: CVE-2026-19052

cve-icon Vulnrichment

Updated: 2026-08-12T12:20:57.595Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T06:21:05.213

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-19052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:15:59Z

Weaknesses