Arbitrary File Upload Vulnerability in Smart Cleaning Theme by WordPress
CVE-2026-74016

9.9CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2026

What is CVE-2026-74016?

The Smart Cleaning Theme for WordPress prior to version 4.8.6 contains a vulnerability that allows authenticated users to upload arbitrary files. This could potentially lead to unauthorized access to the server and execution of malicious code. Webmasters using this theme are advised to update to the latest version to mitigate this risk and protect their websites from potential exploits.

Affected Version(s)

Smart Cleaning <= 4.8.6

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Denver Jackson | Patchstack Bug Bounty Program
.