{"id":"CVE-2026-19056","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-19056","summary":"The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading…","details":"The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request.","published":"2026-08-19T06:17:39.363","modified":"2026-08-19T06:17:39.363","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://wpscan.com/vulnerability/83ad2038-3755-40a5-a8af-e6fac94341d1/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T06:17:39.363"}}