CVE-2026-14524 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 22:05pm

A security vulnerability has been identified in the ProSolution WP Client plugin for WordPress, affecting all versions up to and including 2.0.8. The flaw stems from the plugin not properly validating file paths when processing file deletion requests, creating a security gap for sites using this tool.

This gap makes it possible for attackers who do not have login access to your website to delete any file stored on your web server. If an attacker deletes a critical file such as your site's core configuration file (wp-config.php), they can take full control of your website, run malicious code, access sensitive data, or cause your site to stop working entirely.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14524

« Back