Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-74018: Warehouse Cargo theme lets attackers upload files

CVE-2026-74018 · published 14 days ago
Summary

The Warehouse Cargo theme for WordPress, up through version 2.6.9, can be tricked into accepting any file an attacker provides. This could let a malicious file be placed on your website, potentially giving the attacker control over the site. Update the theme to a newer version or replace it with a safe alternative as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
themagnifico52 warehouse cargo <= 2.6.9
Original advisory text
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Severity
9.9 Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published20 Aug 2026
Updated3 Sep 2026
First seen20 Aug 2026
Sources
CVE-2026-74018 · MITRE
Monitor software like this
Free during beta