Junglewise Threat Intelligence

CVE-2026-74016: Smart Cleaning arbitrary file upload in WordPress theme

CVE-2026-74016 · Severity: critical · CVSS 9.9 · Published 2026-08-20

Executive brief

The Smart Cleaning WordPress theme contains a critical vulnerability that allows authenticated subscribers to upload arbitrary files to a WordPress site. An attacker with a basic subscriber account can exploit this flaw to upload malicious code, potentially taking control of the entire website and compromising customer data or using it for further attacks.

Technical details

The Smart Cleaning WordPress theme (versions 4.8.6 and earlier) is vulnerable to arbitrary file upload via insufficient validation of user-supplied file uploads. The vulnerability allows authenticated subscribers (low-privilege users) to upload malicious files to the server without proper restrictions on file type or location. No authentication bypass is required—the attacker simply needs a basic subscriber account, which is often easy to obtain. Successful exploitation enables remote code execution and full server compromise. As of the advisory date, no official patch is available; the theme has not been updated in two months and is unlikely to receive fixes.

Affected products

  • Smart Cleaning Smart Cleaning 4.8.6 and earlier

Timeline

  • 2026-08-20: disclosed: Published on NVD and Patchstack
  • 2026-02-22: other: Originally reported by Denver Jackson

References