CVE-2026-74016
Deferred Deferred - Pending Action

Subscriber Arbitrary File Upload in Smart Cleaning

Vulnerability report for CVE-2026-74016, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: Patchstack

Description

Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
patchstack smart_cleaning to 4.8.6 (exc)
smart_cleaning subscriber_arbitrary_file_upload to 4.8.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Arbitrary File Upload flaw in the WordPress Smart Cleaning Theme versions 4.8.6 and below. It allows attackers to upload any file type to the website, potentially including malicious backdoors for further unauthorized access.

Impact Analysis

Attackers could exploit this to upload harmful files, gain control of the website, steal data, or use it as a launch point for further attacks. The high CVSS score of 9.9 indicates severe potential impact.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for data protection and security. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Apply Patchstack's mitigation rule to block attacks until an official patch is available. Deactivate the Smart Cleaning Theme if possible and seek assistance from a hosting provider or web developer for further mitigation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74016. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart