CVE-2026-74018: WordPress Warehouse Cargo theme <= 2.6.9 - Arbitrary File Upload vulnerability
Published Aug 20, 2026
·Updated
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Affected Software
1 affected component
WordPress Warehouse Cargo theme<=2.6.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Warehouse Cargo themeto a version that resolves this vulnerability.Fixed in 2.6.9
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs a WordPress account with the Subscriber role or equivalent low-privileged authenticated access. No user interaction is required.
2
What is the potential impact?
The vulnerability allows arbitrary file upload and is rated critical, with potential for high confidentiality, integrity, and availability impact. Its scope is changed, meaning the impact can extend beyond the vulnerable component.
3
Which versions are affected?
Warehouse Cargo theme versions 2.6.9 and earlier are affected.