CVE-2026-16098 (matched: wordpress)

  • Tuesday, 18th August, 2026
  • 16:04pm

A security flaw has been identified in the ProSolution WP Client plugin for WordPress, affecting all versions up to and including 2.0.10. The vulnerability allows unauthenticated visitors (people who do not have login access to your WordPress dashboard) to upload files to your website.

This is possible due to gaps in two key security safeguards for the plugin's file upload feature. A check meant to block dangerous file types can be tricked, and an access control intended to stop unauthenticated users from reaching the upload tool is accidentally exposed on public pages of sites using the plugin's job portal shortcode. This lets attackers obtain valid access to the upload feature and bypass the intended block entirely.

If an attacker is able to upload a file that can execute code on your server, they could gain full control of your website, make unauthorized changes to your content, steal sensitive customer or business data, or abuse your hosting account for other malicious activity.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-16098

« Back