Arbitrary File Upload Vulnerability in Warehouse Cargo Theme by Patchstack
CVE-2026-74018

9.9CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2026

What is CVE-2026-74018?

An arbitrary file upload vulnerability exists in the Warehouse Cargo theme for WordPress, impacting versions up to 2.6.9. This security flaw could allow unauthorized users to upload malicious files to the server, potentially leading to remote code execution. Users of the Warehouse Cargo theme are urged to update to the latest version immediately to mitigate any risks associated with this vulnerability.

Affected Version(s)

Warehouse Cargo <= 2.6.9

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Denver Jackson | Patchstack Bug Bounty Program
.