CVE-2026-2942Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-04-08); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-04-08: 4Mentions · 2026-04-09: 2Mentions · 2026-04-27: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-08: 4Technical Details · 2026-04-09: 2Technical Details · 2026-04-27: 104-0804-0904-27
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-084
Disclosure3Patch1
2026-04-092
Disclosure1General1
2026-04-271
Patch1
Full discourse7 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-2942 — CVSS 9.8/10 ██████████ The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/D4h4paI4xp

    Post summary

    The tweet alerts about critical CVE‑2026‑2942 in the ProSolution WP Client plugin that permits arbitrary file uploads because of missing file type validation and urges users to apply the available patch immediately.

    1000038
    16 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    CVE-2026-2942 – Critical WordPress Plugin Flaw The ProSolution WP Client plugin (≤1.9.9) allows unauthenticated file uploads due to missing validation. What’s the risk: Attackers can upload malicious files → gain remote code execution → full site takeover. Business impact: • Payment skimmers injected • Customer data theft • SEO spam & blacklisting • Revenue loss + recovery costs How to protect your site: • Update or remove the plugin immediately • Audit uploads & server files • Restrict file types + enforce WAF rules • Continuously scan for hidden malware Don’t wait for exploitation — scan now 👉 https://quttera.com/wordpress-malware-scanner #WordPress #WooCommerce #CyberSecurity #CVE #WebSecurity #SilentRisk

    Post summary

    The message announces a critical WordPress plugin flaw that allows unauthenticated file uploads leading to remote code execution and urges immediate patching or removal.

    0000048
    40 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-2942 | CVSS 9.8 🔴 CVE-2026-25776 | CVSS 9.3 🔴 CVE-2025-14815 | CVSS 9.3 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post merely lists three CVEs with their CVSS scores and a link to a vulnerability page, providing no further details on exploits, patches, or technical aspects.

    00000317
    5.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2942: CRITICAL] WordPress ProSolution WP Client plugin up to version 1.9.9 allows unauthenticated attackers to upload arbitrary files, posing a severe security risk and enabling potential remote code...#cve,CVE-2026-2942,#cybersecurity https://cvefind.com/CVE-2026-2942

    Post summary

    A critical vulnerability (CVE‑2026‑2942) in WordPress ProSolution WP Client plugin (≤1.9.9) allows unauthenticated file uploads that can lead to remote code execution.

    0000044
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2942 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in… https://www.cve.org/CVERecord?id=CVE-2026-2942

    Post summary

    The excerpt discloses CVE‑2026‑2942, noting an arbitrary file upload flaw in a WordPress plugin caused by missing file type validation.

    00000130
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-2942: ProSolution WP Client <= 1.9.9 - ... Unauthenticated file upload with zero validation = instant webshell deployment on 9.8 CVSS - WordPress admins better pat... https://zerodaysignal.com/vulnerability/CVE-2026-2942 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-2942 exposes an unauthenticated file upload flaw in ProSolution WP Client (≤1.9.9) that can be exploited to deploy a webshell immediately, and the vulnerability carries a high CVSS score of 9.8.

    0000060
    204 followersView on X
  • Abu Hurayra 🇵🇸❤️🇧🇩@HurayraIIT
    Disclosure

    CVE-2026-2942: Critical Unauthenticated Arbitrary File Upload in ProSolution WP Client (CVSS 9.8) https://hurayraiit.com/blog/cve-2026-2942-prosolution-wp-client-arbitrary-file-upload/

    Post summary

    The post publicly announces CVE‑2026‑2942, a critical unauthenticated arbitrary file upload flaw in ProSolution WP Client, and provides core technical details such as the attack vector and CVSS score.

    0000039
    85 followersView on X

Explore more