CVE-2026-14524 (matched: wordpress)

  • Monday, 17th August, 2026
  • 10:07am

A security vulnerability has been identified in the ProSolution WP Client plugin for WordPress, impacting all versions of the plugin up to and including 2.0.8. If your WordPress site uses this plugin, it is at risk: the flaw allows unauthenticated attackers (people who do not have login credentials for your site) to delete arbitrary files stored on the server that hosts your website.

This is a high-severity issue because deleting specific core WordPress files, such as your site's main configuration file (wp-config.php), can give an attacker full control of your website. This could lead to stolen visitor data, defaced site content, or your site being used to distribute harmful content to your visitors.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-14524

« Back