Arbitrary File Upload Vulnerability in ProSolution WP Client Plugin for WordPress
CVE-2026-6555
9.8CRITICAL
What is CVE-2026-6555?
The ProSolution WP Client plugin for WordPress, up to version 2.0.0, exhibits a significant vulnerability that allows for arbitrary file uploads. This arises from an array validation issue where the initial file in the upload array is subjected to extension and MIME type checks, but subsequent files are not. As a result, unauthenticated attackers can exploit this flaw to upload malicious PHP files disguised as legitimate content, potentially resulting in remote code execution. Administrators are advised to update to the latest version of the plugin to mitigate this risk.
Affected Version(s)
ProSolution WP Client 0 <= 2.0.0