A security flaw has been found in the ProSolution WP Client plugin for WordPress, impacting all versions up to and including 2.0.8. The plugin does not properly validate file paths, which allows unauthenticated attackers (people who do not have login credentials for your WordPress site) to easily delete arbitrary files stored on your web server, using only publicly accessible site features. If an attacker deletes the right critical file, such as WordPress’s core configuration file, they can gain full control of your website. This lets them run their own code on your site, which could lead to stolen customer data, injected malicious content, or your site being used for other harmful activity.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14524