A security flaw has been found in the ProSolution WP Client plugin for WordPress, which impacts all versions of the plugin up to and including 2.0.8. This vulnerability lets people who do not have any login access to your website delete arbitrary files stored on your web server, because the plugin fails to properly validate file paths when processing deletion requests.
If an attacker deletes the correct critical file on your server, such as the core WordPress configuration file, they can gain full control of your website. The attack can be carried out using only publicly accessible features of your site, with no need for the attacker to have any pre-existing access or login credentials.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14524