CVE-2026-74016: WordPress Smart Cleaning theme <= 4.8.6 - Arbitrary File Upload vulnerability
Published Aug 20, 2026
·Updated
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
Affected Software
1 affected component
WordPress Smart Cleaning theme<=4.8.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Smart Cleaning themeto a version that resolves this vulnerability.Fixed in 4.8.6
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Smart Cleaning theme installations running version 4.8.6 or earlier are affected.
2
What access does an attacker need to exploit this issue?
The attacker needs Subscriber-level privileges. Exploitation is network-accessible, requires low attack complexity, and does not require user interaction.
3
What is the potential impact of successful exploitation?
The vulnerability can lead to high-impact compromise of confidentiality, integrity, and availability. Its CVSS vector also indicates that the impact can extend beyond the initially affected security scope.