Executive brief
The ProSolution WP Client plugin for WordPress, which is used to manage client interactions, contains a security flaw that allows unauthorized users to upload files to the website's server. Because the plugin does not verify the type of files being uploaded, an attacker could upload malicious scripts to take full control of the website. This could lead to the theft of sensitive customer data, website defacement, or a total service outage.
Technical details
The ProSolution WP Client plugin for WordPress is vulnerable to an unrestricted file upload flaw (CWE-434) within the 'proSol_fileUploadProcess' function. The vulnerability stems from a lack of file type validation, allowing unauthenticated remote attackers to upload arbitrary files, including PHP scripts, to the server. By executing these uploaded scripts, an attacker can achieve remote code execution (RCE), leading to full system compromise. The issue affects all versions of the plugin up to and including 1.9.9. A patch has been identified in subsequent changesets.
Affected products
- prosolution ProSolution WP Client up to, and including, 1.9.9
Timeline
- 2026-04-08: advisory: Initial disclosure by Wordfence and NVD
- 2026-04-08: disclosed
References
- https://plugins.trac.wordpress.org/browser/prosolution-wp-client/trunk/public/class-prosolwpclient-public.php?rev=3331282
- https://plugins.trac.wordpress.org/changeset/3484577/prosolution-wp-client
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3852aef6-42e7-4b71-a1ba-dd41284fd07b?source=cve