Executive brief
Warehouse Cargo is a WordPress theme used by many websites to display products and content. A vulnerability allows any logged-in subscriber to upload malicious files to the server, potentially leading to complete site compromise, data theft, and use of the server for hosting malware or launching attacks on other systems.
Technical details
The vulnerability is an arbitrary file upload flaw in Warehouse Cargo WordPress theme versions up to 2.7.1 that allows authenticated users with subscriber-level privileges to bypass file upload restrictions. The root cause lies in insufficient validation of uploaded file types and placement. An attacker with subscriber access can exploit this to upload executable files (e.g., PHP shells) to the server, achieving remote code execution and full server compromise. No official patch has been released as of the advisory date; Patchstack offers a mitigation rule as a temporary measure.
Affected products
- Warehouse Cargo Warehouse Cargo <= 2.7.1
Timeline
- 2026-08-20: disclosed