A security flaw tracked as CVE-2026-14524 has been identified in the ProSolution WP Client plugin for WordPress, impacting all versions up to and including 2.0.8. The vulnerability stems from insufficient validation of file paths when the plugin processes file deletion requests.
This flaw allows unauthenticated attackers (people who do not have login credentials for your WordPress site) to delete arbitrary files stored on your server. If an attacker deletes critical core files such as wp-config.php, they can gain full control of your website and run unauthorized code on it.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14524