Detects the ProSolution WP Client plugin for WordPress versions up to 1.9.9 where the proSol_fileUploadProcess AJAX handler trusts the client-supplied MIME type via proSol_mimeExt(), which allows all file extensions including .php. The handler is registered on wp_ajax_nopriv (unauthenticated). An attacker can upload a PHP webshell and achieve full remote code execution.
Is your app exploitable through CVE-2026-2942?
Scan your domain free