Junglewise Threat Intelligence

CVE-2026-74018: Warehouse Cargo arbitrary file upload

CVE-2026-74018 · Severity: critical · CVSS 9.9 · Published 2026-08-20

Executive brief

Warehouse Cargo is a WordPress theme used by many websites to display products and content. A vulnerability allows any logged-in subscriber to upload malicious files to the server, potentially leading to complete site compromise, data theft, and use of the server for hosting malware or launching attacks on other systems.

Technical details

The vulnerability is an arbitrary file upload flaw in Warehouse Cargo WordPress theme versions up to 2.7.1 that allows authenticated users with subscriber-level privileges to bypass file upload restrictions. The root cause lies in insufficient validation of uploaded file types and placement. An attacker with subscriber access can exploit this to upload executable files (e.g., PHP shells) to the server, achieving remote code execution and full server compromise. No official patch has been released as of the advisory date; Patchstack offers a mitigation rule as a temporary measure.

Affected products

  • Warehouse Cargo Warehouse Cargo <= 2.7.1

Timeline

  • 2026-08-20: disclosed

References