CVE-2026-2942

ProSolution WP Client <= 1.9.9 - Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.


We have discovered 4 live websites that are affected by CVE-2026-2942.

Run a Free Instant Scan




Affected Software

Product  Prosolution Wp Client
Category Wordpress Plugins
Vulnerable Domains4 live websites (100% of Prosolution Wp Client install base)
Vulnerable Versions
  • from 0 through 1.9.9
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Apr 8, 2026
  • Updated - Apr 8, 2026

Credits

  • Nabil Irawan (finder)

Website Distribution by Country

Number of websites using CVE-2026-2942
Austria3 websites
Germany1 websites

Website Distribution by TLD

Number of websites using CVE-2026-2942
.at4 websites

Websites affected by CVE-2026-2942

Top websites that are affected by CVE-2026-2942. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.at Austria**,***,***
******.at Austria**,***,***
********.*********.at Austria**,***,***
*********.at Germany**,***,***
See full domain list

FAQ

CVE-2026-2942 is Unrestricted Upload of File with Dangerous Type in Prosolution Wp Client
A total of 4 websites have been identified as vulnerable to CVE-2026-2942, based on global website indexing conducted by WebTechSurvey.
The Prosolution Wp Client is affected by the CVE-2026-2942 vulnerability.
Prosolution Wp Client versions up to and including 1.9.9 are vulnerable to CVE-2026-2942.