Arbitrary File Upload Vulnerability in ProSolution WP Client Plugin for WordPress
CVE-2026-6555

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 May 2026

What is CVE-2026-6555?

The ProSolution WP Client plugin for WordPress, up to version 2.0.0, exhibits a significant vulnerability that allows for arbitrary file uploads. This arises from an array validation issue where the initial file in the upload array is subjected to extension and MIME type checks, but subsequent files are not. As a result, unauthenticated attackers can exploit this flaw to upload malicious PHP files disguised as legitimate content, potentially resulting in remote code execution. Administrators are advised to update to the latest version of the plugin to mitigate this risk.

Affected Version(s)

ProSolution WP Client 0 <= 2.0.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Achmad Zaenuri Dahlan Putra
.