Impact
The Warehouse Cargo WordPress theme versions up to 2.6.9 allow a subscriber to upload any file through the theme’s file upload interface. Uploading a malicious file can lead to execution of that code on the WordPress server, offering attackers full control over the compromised site. This flaw is classified as CWE‑434, an arbitrary file upload weakness.
Affected Systems
Any WordPress installation using the Warehouse Cargo theme from the developer themagnifico52 with version 2.6.9 or earlier is affected. Sites that rely on the theme for front‑end functionality and user interaction are within the scope.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.9, indicating critical severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, but the high CVSS rating and the potential for user‑level payload submission make exploitation a significant risk. Attackers can likely exploit the flaw through the WordPress environment, typically by logging in as a subscriber and using the upload feature to submit a malicious file. Given the lack of mitigation from the vendor, the risk remains high until a patch is applied.
OpenCVE Enrichment