A serious security vulnerability, tracked as CVE-2026-16098, affects the ProSolution WP Client plugin for WordPress in all versions up to and including 2.0.10. This flaw allows unauthenticated attackers (people who do not have login access to your WordPress dashboard) to upload dangerous executable files to your website. Once these files are in place, attackers can run harmful code on your site remotely, which could let them take control of your site, steal visitor or customer data, or use your site to spread malware to people who visit it.
This vulnerability is extremely easy to exploit, even for attackers with minimal technical skill. The plugin’s upload protection relies on a security token that is publicly visible on any page of your site that uses the plugin’s job portal feature. Any random visitor to these pages can access this token to bypass the upload restrictions entirely, with no login or special access required.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16098