ProSolution WP Client < 2.0.11 - Reflected XSS via Multiple Parameters
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.1epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Affected products
Unknown · ProSolution WP Clientpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/a1243ff3-3f0e-4068-a716-722e7cf4856b/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.