CVE-2026-2942 is an arbitrary file upload vulnerability in the ProSolution WP Client plugin for WordPress affecting all versions up to and including 1.9.9. The flaw is caused by missing file type validation in the proSol_fileUploadProcess function. Because uploaded content is not properly restricted to safe file types, an unauthenticated attacker can submit arbitrary files to the server through the plugin's upload functionality. If the uploaded file is placed in an executable or otherwise reachable location, the issue can lead to remote code execution on the affected WordPress host.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a small standalone exploit project with 2 files: a Python exploit/scanner (CVE-2026-2942.py) and a README documenting the vulnerability, manual PoC steps, usage, and mitigation guidance. The code targets ProSolution WP Client for WordPress, version <= 1.9.9, and exploits an unauthenticated arbitrary file upload that leads to remote code execution. The exploit workflow is: (1) discover a valid nonce from a public page that renders the [prosolfrontend] shortcode, using homepage fetches, sitemap enumeration, common slug probing, optional REST nonce endpoints, and fallback AJAX nonce actions; (2) submit a PHP payload to /wp-admin/admin-ajax.php using the vulnerable action proSol_fileUploadProcess while spoofing the MIME type as image/jpeg; (3) parse the server response to recover the renamed uploaded filename under /wp-content/uploads/prosolwpclient/; and (4) optionally verify RCE by requesting the uploaded PHP shell with a command parameter. Capabilities include single-target exploitation, bulk scanning from a target list, multithreaded execution, proxy support, timeout control, output logging, and multiple selectable PHP shell payload styles (system, passthru, exec, assert, base64-eval, and a fuller fallback shell). This is not merely a detector: it actively uploads a webshell and can execute commands, making it a real exploit. Because the payloads are built-in and basic rather than framework-driven or highly modular, the maturity is best classified as OPERATIONAL. Fingerprintable target-side artifacts include WordPress sitemap paths, REST nonce endpoints, the admin AJAX endpoint, the vulnerable AJAX action name, and the upload directory /wp-content/uploads/prosolwpclient/. The README also confirms the expected exploitation chain and resulting shell URL structure. Overall, the repository’s purpose is to automate discovery and exploitation of the vulnerable plugin to achieve unauthenticated PHP webshell upload and command execution.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior unauthenticated arbitrary file upload vulnerability in the ProSolution WP Client plugin affecting versions up to 1.9.9, referenced as related background to the current flaw.
An arbitrary file upload vulnerability in the ProSolution WP Client plugin for WordPress caused by missing file type validation in the 'proSol_fileUploadProcess' function, affecting all versions up to and including 1.9.9 and potentially enabling remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.