Vulnerability
Published 2026-08-12
Verified 2026-09-19

WordPress 7.0.4: authenticated Imagick/Ghostscript upload RCE (CVE-2026-65640)

WordPress 7.0.4 (12 August 2026) is a security release. An Author or anyone with upload_files can upload a malicious PostScript file and reach remote code execution, but only where Imagick and Ghostscript are both in use. WordPress credits pwn.ai. GitHub advisory GHSA-8vr3-7mxf-gx8w scores it 8.8 (CVSS 3.0). Fixed in 7.0.4, with backports through the 4.7 branch (6.9.7, 6.8.8, and the matching older branch builds). No exploitation claim on the WordPress or GitHub notices.

Product
WordPress core
Versions
7.0.0-7.0.3, and older branches back through 4.7 before the matching backport
CVSS
(CVSS 3.0, GitHub advisory)
Exploited in Australia?
unknown
Patch to
7.0.4, or the backport for the branch you run (6.9.7, 6.8.8, through 4.7.35)

Primary: WordPress 7.0.4 release · Vendor: GHSA-8vr3-7mxf-gx8w · CVE: CVE-2026-65640

vulnerabilities cloud