Impact
The ProSolution WP Client WordPress plugin before version 2.0.11 fails to sanitise and escape several parameters before reflecting them into HTML attributes on its public pages. This oversight results in a reflected Cross‑Site Scripting vulnerability that can be triggered against any visitor, including logged‑in administrators, by inserting malicious scripts into the reflected content.
Affected Systems
WordPress sites that have the ProSolution WP Client plugin with a version earlier than 2.0.11. The vulnerability is confined to the plugin; no specific operating system, database, or server details are supplied.
Risk and Exploitability
The CVSS score of 7.1 categorises the flaw as medium‑to‑high severity, while an EPSS score below 1 % indicates a low probability of active exploitation. It is not listed in the CISA KEV catalog. Attackers can exploit the defect by crafting URLs or inputs containing malicious payloads that are reflected into page content, affecting all visitors who load the vulnerable pages.
OpenCVE Enrichment