Arbitrary File Upload Vulnerability in Warehouse Cargo Theme by Patchstack
CVE-2026-74018
9.9CRITICAL
What is CVE-2026-74018?
An arbitrary file upload vulnerability exists in the Warehouse Cargo theme for WordPress, impacting versions up to 2.6.9. This security flaw could allow unauthorized users to upload malicious files to the server, potentially leading to remote code execution. Users of the Warehouse Cargo theme are urged to update to the latest version immediately to mitigate any risks associated with this vulnerability.
Affected Version(s)
Warehouse Cargo <= 2.6.9