All verified exploits

CVE-2026-2942 Unauthenticated Arbitrary File Upload via ProSolution WP Client

Deterministic critical WordPress Added cve-verified-cve-2026-2942

Detects the ProSolution WP Client plugin for WordPress versions up to 1.9.9 where the proSol_fileUploadProcess AJAX handler trusts the client-supplied MIME type via proSol_mimeExt(), which allows all file extensions including .php. The handler is registered on wp_ajax_nopriv (unauthenticated). An attacker can upload a PHP webshell and achieve full remote code execution.

Related WordPress exploits

Is your app exploitable through CVE-2026-2942?

Scan your domain free