WordPress Plugin Vulnerabilities

ProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion via 'removesite' Cookie

Description

The plugin does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the plugin stores.

Proof of Concept

Affects Plugins

References

Classification

Type
SQLI
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Nir Yehoshua
Submitter
Nir Yehoshua
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-06 (about 4 days ago)
Added
2026-08-06 (about 3 days ago)
Last Updated
2026-08-07 (about 2 days ago)

Other