Description
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
Published: 2026-08-20
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Smart Cleaning theme through version 4.8.6 contains an arbitrary file upload flaw in the subscriber module that allows an attacker to upload any file type. This can be abused to place malicious scripts on the server, leading to arbitrary code execution, data exfiltration, or full site compromise. The weakness is a file upload validation issue catalogued as CWE-434.

Affected Systems

WordPress sites that have the Smart Cleaning theme 4.8.6 or earlier installed are affected. The issue arises when the subscriber feature processes file uploads without proper restriction of file type or sanitization.

Risk and Exploitability

The CVSS score of 9.9 marks this problem as critical, while the EPSS score is not available and the vulnerability is not currently listed in CISA KEV. The likely attack vector is unauthenticated or low‑privileged submission via the theme’s file upload form, which means an opportunistic attacker with internet access can exploit the flaw if the site permits file uploads through the theme functionality.

Generated by OpenCVE AI on August 20, 2026 at 22:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Smart Cleaning to the latest version (≥4.8.7) provided by the vendor.
  • Disable or remove the theme’s file upload capability until a secure patch is applied.
  • If an update cannot be applied, replace the theme with a secure alternative or delete the theme from the installation.

Generated by OpenCVE AI on August 20, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Themagnifico52
Themagnifico52 smart Cleaning
Wordpress
Wordpress wordpress
Vendors & Products Themagnifico52
Themagnifico52 smart Cleaning
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
Title WordPress Smart Cleaning theme <= 4.8.6 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Themagnifico52 Smart Cleaning
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T18:43:11.871Z

Reserved: 2026-08-14T10:16:17.543Z

Link: CVE-2026-74016

cve-icon Vulnrichment

Updated: 2026-08-20T18:43:07.184Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:37.317

Modified: 2026-08-20T19:17:03.530

Link: CVE-2026-74016

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:09:41Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type