Junglewise Threat Intelligence

CVE-2026-74014: IT Residence arbitrary file upload

CVE-2026-74014 · Severity: critical · CVSS 9.9 · Published 2026-08-20

Executive brief

IT Residence is a WordPress theme used to build and customize WordPress websites. A vulnerability in versions 3.2.1 and earlier allows attackers with subscriber-level access to upload malicious files to the server, potentially enabling complete site takeover and deployment of malware or ransomware to all visitors.

Technical details

The IT Residence WordPress theme contains an arbitrary file upload vulnerability requiring only subscriber-level privileges to trigger. The vulnerability allows unauthenticated or low-privileged users to bypass file type validation and upload malicious executable files to the web server. No official patch has been released; Patchstack has implemented a mitigation rule to block attack attempts. The vulnerability is expected to see widespread exploitation due to its high severity and ease of exploitation.

Affected products

  • IT Residence IT Residence <= 3.2.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: advisory: Patchstack issued mitigation rule; no official patch available
  • 2026-02-22: other: Vulnerability initially reported by Denver Jackson

References