The ProSolution WP Client WordPress plugin before version 2.0.11 does not sanitize and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request. This vulnerability affects WordPress installations using the ProSolution WP Client plugin. The plu [truncated]
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator. This vulnerability can have significant impacts on the security of WordPress installations using the ProSolution WP [truncated]
The ProSolution WP Client WordPress plugin before 2.0.9 has a vulnerability allowing unauthenticated users to read arbitrary data from the database and delete records due to improper sanitization of a cookie value used in SQL queries. This vulnerability affects WordPress sites using the plugin, potentially leading to unauthorized access to sensitive data. Administrators should be aware of this vulnerabili [truncated]
The ProSolution WP Client plugin for WordPress contains a critical arbitrary file upload vulnerability affecting versions up to and including 2.0.0. The flaw stems from an array validation mismatch in the file upload handling logic: only the first file in a multi-file upload array undergoes extension and MIME type validation, while all files in the array are subsequently processed and uploaded to a web-ac [truncated]