Junglewise Threat Intelligence

CVE-2026-2942: ProSolution WP Client arbitrary file upload in proSol_fileUploadProcess

CVE-2026-2942 · Severity: critical · CVSS 9.8 · Published 2026-04-08

Technologies: ProSolution WP Client. Vendors: ProSolution.

Executive brief

The ProSolution WP Client plugin for WordPress, which is used to manage client interactions, contains a security flaw that allows unauthorized users to upload files to the website's server. Because the plugin does not verify the type of files being uploaded, an attacker could upload malicious scripts to take full control of the website. This could lead to the theft of sensitive customer data, website defacement, or a total service outage.

Technical details

The ProSolution WP Client plugin for WordPress is vulnerable to an unrestricted file upload flaw (CWE-434) within the 'proSol_fileUploadProcess' function. The vulnerability stems from a lack of file type validation, allowing unauthenticated remote attackers to upload arbitrary files, including PHP scripts, to the server. By executing these uploaded scripts, an attacker can achieve remote code execution (RCE), leading to full system compromise. The issue affects all versions of the plugin up to and including 1.9.9. A patch has been identified in subsequent changesets.

Affected products

  • prosolution ProSolution WP Client up to, and including, 1.9.9

Timeline

  • 2026-04-08: advisory: Initial disclosure by Wordfence and NVD
  • 2026-04-08: disclosed

References