Description
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Published: 2026-08-20
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Warehouse Cargo WordPress theme versions up to 2.6.9 allow a subscriber to upload any file through the theme’s file upload interface. Uploading a malicious file can lead to execution of that code on the WordPress server, offering attackers full control over the compromised site. This flaw is classified as CWE‑434, an arbitrary file upload weakness.

Affected Systems

Any WordPress installation using the Warehouse Cargo theme from the developer themagnifico52 with version 2.6.9 or earlier is affected. Sites that rely on the theme for front‑end functionality and user interaction are within the scope.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.9, indicating critical severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, but the high CVSS rating and the potential for user‑level payload submission make exploitation a significant risk. Attackers can likely exploit the flaw through the WordPress environment, typically by logging in as a subscriber and using the upload feature to submit a malicious file. Given the lack of mitigation from the vendor, the risk remains high until a patch is applied.

Generated by OpenCVE AI on August 20, 2026 at 21:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Warehouse Cargo theme to the latest available version or remove the theme if it is no longer required.
  • Restrict file upload capabilities for non‑admin user roles so that only administrators can upload files.
  • Configure WordPress or a security plugin to whitelist safe file types (e.g., images) and reject all other upload attempts.
  • Monitor the site for unexpected file uploads and conduct integrity checks on theme files to detect unauthorized changes.

Generated by OpenCVE AI on August 20, 2026 at 21:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Themagnifico52
Themagnifico52 warehouse Cargo
Wordpress
Wordpress wordpress
Vendors & Products Themagnifico52
Themagnifico52 warehouse Cargo
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Title WordPress Warehouse Cargo theme <= 2.6.9 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Themagnifico52 Warehouse Cargo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T14:35:42.597Z

Reserved: 2026-08-14T10:16:17.543Z

Link: CVE-2026-74018

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:37.440

Modified: 2026-08-20T15:18:37.610

Link: CVE-2026-74018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:09:40Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type