17/08/2026
๐จ ๐๐๐๐๐๐๐๐ ๐๐๐๐๐๐๐๐ ๐๐๐๐๐ | ๐๐๐-๐๐๐๐-๐๐๐๐๐ ๐จ
A critical Unauthenticated Arbitrary File Upload vulnerability has been identified in the ProSolution WP Client WordPress plugin. Tracked as CVE-2026-16098, the flaw allows a remote attacker to upload arbitrary files without authentication, potentially leading to Remote Code Ex*****on (RCE) and complete compromise of the affected WordPress website.
The vulnerability stems from improper validation of uploaded files and a publicly exposed nonce, allowing attackers to bypass authentication and execute malicious code on vulnerable servers.
โ ๏ธ ๐๐๐๐๐๐ญ๐๐ ๐๐๐ซ๐ฌ๐ข๐จ๐ง๐ฌ
โข ProSolution WP Client 2.0.10 and earlier
โ
๐๐๐๐จ๐ฆ๐ฆ๐๐ง๐๐๐ ๐๐๐ญ๐ข๐จ๐ง๐ฌ
โ Upgrade to the latest patched version as soon as it becomes available.
โ Disable the plugin or its file upload functionality if an update is unavailable.
โ Restrict access to upload endpoints and disable PHP ex*****on in upload directories.
โ Conduct a comprehensive security assessment to identify potential exposure.
๐ก๏ธ ๐๐จ๐ฐ ๐๐๐๐๐๐๐ ๐๐๐๐ ๐๐๐ง ๐๐๐ฅ๐ฉ
โข Vulnerability Assessment & Pe*******on Testing (VAPT)
โข Web Application Security Testing
โข WordPress Security Assessment
โข Threat Intelligence
โข Incident Response
Stay Alert. Patch Promptly. Secure Your WordPress Environment.
๐ Learn More
๐๐๐: https://www.cve.org/CVERecord?id=CVE-2026-16098
*****on