CRITICAL 9.9 CVE-2026-74016 Published 20 Aug 2026

WordPress Smart Cleaning Plugin Arbitrary File Upload

Worried this affects one of your servers?

WordPress plugin Smart Cleaning versions 4.8.6 and earlier are affected by an arbitrary file upload vulnerability.

This flaw allows subscribers to upload arbitrary files, which could lead to remote code execution.

To mitigate, update to the latest version (4.8.7) or higher.

Reference: CVE-2026-74016 on NVD

← Back to Security News