CVE-2026-16098Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delete the already-written file. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce required to reach the upload handler is publicly exposed via wp_localize_script on any front-end page rendering the job portal shortcode, allowing unauthenticated visitors to obtain a valid nonce and bypass that gating check entirely.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-16); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-08-16: 3Mentions · 2026-08-17: 2PoC Mentioned / Linked · 2026-08-16: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-16: 3Technical Details · 2026-08-17: 108-1608-17
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-08-163
Disclosure2Patch1
2026-08-172
Disclosure2
Full discourse5 posts
  • RootNik Labs@rootniklabs
    Disclosure

    🚨 𝐂𝐑𝐈𝐓𝐈𝐂𝐀𝐋 𝐒𝐄𝐕𝐄𝐑𝐈𝐓𝐘 𝐀𝐋𝐄𝐑𝐓 | 𝐂𝐕𝐄-𝟐𝟎𝟐𝟔-𝟏𝟔𝟎𝟗𝟖 🚨 🔗 Learn More 𝐂𝐕𝐄: https://www.cve.org/CVERecord?id=CVE-2026-16098 #CVE202616098 #RCE #ApplicationSecurity #ThreatIntelligence #VulnerabilityManagement #PatchManagement #Info #RootNikLabs https://t.co/1GljPYybTS

    Post summary

    The tweet issues a critical severity alert for CVE‑2026‑16098, noting its RCE nature and urging awareness, but it does not provide any technical, exploit, or mitigation details.

    0001052
    273 followersView on X
  • techs_targe@techs44576
    Disclosure

    エージェント収集レポート Daily Report 2026.8.17 ■セキュリティ・AI Safety関連 AI Safety 側は新規採用なしで、今日は WordPress とアーカイブ処理の確認が中心です。 ProSolution WP Client CVE-2026-16098 は未認証で任意ファイルをアップロードできる。公開ジョブポータルがあれば更新確認を先に。 https://nvd.nist.gov/vuln/detail/CVE-2026-16098 Pandora CVE-2026-74764 は TAR 展開で抽出先外へファイルを書ける。外部アーカイブの取込経路があれば更新確認を進めたい。 https://nvd.nist.gov/vuln/detail/CVE-2026-74764 ARForms CVE-2024-13784 は 1.8.5 以下の PHP Object Injection。別 plugin / theme の POP chain 併存有無まで確認したい。 https://nvd.nist.gov/vuln/detail/CVE-2024-13784 ■claude code update 由来 上流は静かで、前回の変更を運用へ当てる確認に向いています。 Claude Code の公開差分はなし。最新公開版は v2.1.233 のままです。 https://github.com/anthropics/claude-code/releases/tag/v2.1.233 ■xTECH 由来 今日の本レポートでは、実装人材、悪意なき暴走、信頼性重視 AI が並んでいます。 IT 大手4社が脱・人月へ FDE を拡充。日立は26年度内に国内 FDE 1000人を目指します。 https://xtech.nikkei.com/atcl/nxt/column/18/00001/11956/ OpenAI と Anthropic の評価で実システムへの未承認アクセス事案。自律動作の境界確認が要ります。 https://xtech.nikkei.com/atcl/nxt/column/18/00682/080600214/ KDDI が Buffmee 開始。書籍・雑誌・Webメディアなど約150コンテンツを情報源にしています。 https://xtech.nikkei.com/atcl/nxt/column/18/00086/00416/ オプトの業務改革に生成 AI を投入。「BPR と呼ばない」が成功条件として挙げられています。 https://xtech.nikkei.com/atcl/nxt/column/18/03076/080300029/

    Post summary

    The daily report discloses three WordPress-related vulnerabilities, detailing their nature (unrestricted file upload, TAR path traversal, PHP Object Injection) and providing NVD links, but it does not mention PoCs, exploits, patches, or active use.

    00001198
    531 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    WordPress sites using ProSolution WP Client plugin face CVE-2026-16098 (CVSS 9.8) arbitrary file upload risk. Update immediately if running 2.0.10 or older. https://nvd.nist.gov/vuln/detail/CV… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/TWpCXNK4rz

    Post summary

    The tweet highlights CVE-2026‑16098, an arbitrary file upload flaw with CVSS 9.8 in the ProSolution WP Client plugin, urging users of version 2.0.10 or older to update immediately, while noting no active exploitation or PoC is referenced.

    0000058
    93 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 ProSolution WP Client — CVSS 9.8 CRITICAL CVE-2026-16098: Unauthenticated arbitrary file upload via proSol_handleFileUpload → https://threataft.com/articles/prosolution-wp-client-cve-2026-16098 #cybersecurity #infosec #WordPress #FileUpload #RCE #CVSS9 #ThreatIntel

    Post summary

    The article announces CVE-2026-16098, a critical arbitrary file‑upload flaw in ProSolution WP Client with CVSS 9.8, but does not provide exploitation details, active usage evidence, or patch information.

    0000054
    36 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-16098 Arbitrary File Upload in ProSolution WP Client Plugin Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-16098

    Post summary

    The text announces CVE‑2026‑16098, an arbitrary file upload flaw in ProSolution WP Client Plugin that permits remote code execution; no PoC, exploit code, active use, patch, or false‑positive claim is provided.

    0000094
    4.1K followersView on X

Explore more