A security flaw has been found in the ProSolution WP Client plugin for WordPress, which affects all versions up to and including 2.0.10. This flaw lets people who do not have admin access to your WordPress site upload harmful files that can run code on your website.
The security check meant to block unapproved file uploads is accidentally visible to the public on any page that uses the plugin's job portal feature. This lets bad actors easily bypass the upload restriction. Once a malicious file is uploaded, attackers can take full control of your website, including its content, customer data, and overall functionality.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16098