216.73.217.22

CVE-2026-6555

· Published 20/05/2026 02:16 · Modified 20/05/2026 13:54

Labels: CVE-2026-6555 2026-05-20CVE-2026-6555CWE-434[email protected]

Essential information

Published
20/05/2026 02:16
Modified
20/05/2026 13:54
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a web-accessible directory. This makes it possible for unauthenticated attackers to upload malicious PHP files and achieve remote code execution by sending a valid first file followed by a malicious file.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
prosolution / wp client cpe:2.3:a:prosolution:wp_client:<2.0.0:*:*:*:*:wordpress:*:*

References