


Perceptive Security
SOC/SIEM Consultancy

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' fun…
Published:
7 april 2026 om 22:00:00
Alert date:
8 april 2026 om 20:02:46
Source:
nvd.nist.gov
Web Technologies
The ProSolution WP Client plugin for WordPress contains a critical arbitrary file upload vulnerability in versions up to 1.9.9. The vulnerability exists in the 'proSol_fileUploadProcess' function due to missing file type validation. Unauthenticated attackers can exploit this flaw to upload arbitrary files to the server, potentially leading to remote code execution. This represents a high-severity security risk for WordPress sites using the affected plugin versions.
Technical details
Mitigation steps:
Affected products:
ProSolution WP Client WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-2942
https://plugins.trac.wordpress.org/browser/prosolution-wp-client/trunk/public/class-prosolwpclient-public.php?rev=3331282#L993
https://plugins.trac.wordpress.org/changeset/3484577/prosolution-wp-client
https://www.wordfence.com/threat-intel/vulnerabilities/id/3852aef6-42e7-4b71-a1ba-dd41284fd07b?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
