LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-2942 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 8, 2026

ProSolution WP Client - Unrestricted File Upload

Published: April 8, 2026Updated: April 8, 2026Remote Exploitable

Overview

ProSolution WP Client WordPress plugin <= 1.9.9 contains an unrestricted file upload vulnerability caused by missing file type validation in 'proSol_fileUploadProcess', letting unauthenticated attackers upload arbitrary files, exploit requires no authentication.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Unauthenticated attackers can upload arbitrary files, potentially leading to remote code execution and full server compromise.

Mitigation

Update to the latest version of ProSolution WP Client plugin.

Details

CVE ID
CVE-2026-2942
Severity
Critical
CVSS Score
9.8
Type
unrestricted_file_upload
Status
unconfirmed

CWE

  • CWE-434

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H