CVE-2026-16098
prosolution ProSolution WP Client
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delete the already-written file. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce required to reach the...
- CVSS
- 9.8
- EPSS
- 0.64% 48.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.16