A security vulnerability (CVE-2026-16098) has been found in the ProSolution WP Client plugin for WordPress, affecting all versions up to and including 2.0.10. This flaw lets unauthenticated (not logged-in) attackers upload files to your website without permission.
These uploaded files can be set to run code on your server, which could let attackers take control of your site, steal visitor data, or alter your site's content and features. The flaw exists because the plugin does not properly validate file names during uploads, and a post-upload security check fails to delete malicious files that pass the initial upload step. The security token meant to block unauthorized access to the upload feature is also accidentally exposed on any public page that uses the plugin's job portal shortcode, so attackers do not need any special access to exploit this flaw.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16098