CVE-2026-16098 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 10:06am

A security flaw has been identified in the ProSolution WP Client plugin for WordPress, a common tool used to add job portal features to websites. All versions of the plugin up to and including 2.0.10 are affected by this vulnerability.

The issue allows unauthenticated attackers (people who do not have login access to your WordPress dashboard) to upload arbitrary files to your site. These uploaded files can be set to run code on your web server, which could lead to full site takeover, stolen visitor or customer data, site defacement, or your site being used to spread malware to your audience.

The plugin had a basic security check meant to block unauthenticated uploads, but this check is fully bypassed. The temporary security code required to access the upload feature is publicly visible on any front-end page of your site that displays the job portal, so any random visitor can access and exploit the upload function without any special credentials.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16098

« Back