Impact
The ProSolution WP Client WordPress plugin before 2.0.9 fails to verify user capabilities for two administrative AJAX actions—proSol_ajaxTablesync and proSol_ajaxClearlog. Because the nonce used for these calls is exposed on the public front‑end, any authenticated user who can log into the site, including subscribers who normally lack admin privileges, can trigger these actions. This allows the attacker to initiate an administrative data synchronization or to clear the plugin’s activity records, effectively altering data integrity and potentially disrupting normal operation.
Affected Systems
The vulnerable component is the ProSolution WP Client plugin deployed on WordPress sites. All releases prior to 2.0.9 are affected. No specific WordPress versions or hosting environments are singled out; the issue exists wherever this plugin is active.
Risk and Exploitability
The missing capability checks and publicly accessible nonce make the flaw exploitable by a legitimate but low‑privilege user. While the exploit does not provide direct code execution, it enables unauthorized data manipulation, which can be leveraged to obscure auditing trails or to trigger unintended synchronization that may impact data consistency. The EPSS score is < 1%, indicating a low probability of exploitation, and the CVSS score of 4.3 reflects moderate impact. The vulnerability is not listed in the CISA KEV catalog, but the potential impact on data integrity warrants prompt remediation.
OpenCVE Enrichment