WORDPRESS · AUGUST 2026 · EARLY WARNING

ProSolution WP Client Plugin Vulnerability: Critical Arbitrary File Deletion

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.1
Affected component
prosolution wp client (wordpress)
Patched version
Not yet available
CVE-2026-14524

An early warning has been issued for a critical vulnerability in the ProSolution WP Client plugin for WordPress. This vulnerability could allow for arbitrary file deletion and potential remote code execution.

What happened

The ProSolution WP Client plugin for WordPress is reportedly vulnerable to arbitrary file deletion due to insufficient file path validation. This vulnerability, tracked as CVE-2026-14524, affects all versions up to and including 2.0.8. An attacker could exploit this by calling specific functions with a crafted path-traversal key, leading to the deletion of critical files and potentially enabling remote code execution.

Additionally, another vulnerability, tracked as CVE-2026-16098, affects versions up to and including 2.0.10. This vulnerability allows for arbitrary file upload due to missing validation of the Content-Disposition header filename. An attacker could upload executable files, further enabling remote code execution.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If prosolution wp client is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using the ProSolution WP Client plugin for WordPress in versions up to and including 2.0.8 or 2.0.10, you may be affected by these vulnerabilities.

What should I do right now?

Monitor the primary sources for updates on patched versions, review server files for any signs of tampering, and consider disabling the plugin until a fix is available.

Has this been exploited in the wild?

There is no confirmed evidence that these vulnerabilities have been exploited in the wild at this time.

Sources

Join the 0Day waitlist →

← Back to all threats