Impact
The Smart Cleaning theme through version 4.8.6 contains an arbitrary file upload flaw in the subscriber module that allows an attacker to upload any file type. This can be abused to place malicious scripts on the server, leading to arbitrary code execution, data exfiltration, or full site compromise. The weakness is a file upload validation issue catalogued as CWE-434.
Affected Systems
WordPress sites that have the Smart Cleaning theme 4.8.6 or earlier installed are affected. The issue arises when the subscriber feature processes file uploads without proper restriction of file type or sanitization.
Risk and Exploitability
The CVSS score of 9.9 marks this problem as critical, while the EPSS score is not available and the vulnerability is not currently listed in CISA KEV. The likely attack vector is unauthenticated or low‑privileged submission via the theme’s file upload form, which means an opportunistic attacker with internet access can exploit the flaw if the site permits file uploads through the theme functionality.
OpenCVE Enrichment