Vulnerability
Published 2026-08-12
Verified 2026-09-19
WordPress 7.0.4: authenticated Imagick/Ghostscript upload RCE (CVE-2026-65640)
WordPress 7.0.4 (12 August 2026) is a security release. An Author or anyone with upload_files can upload a malicious PostScript file and reach remote code execution, but only where Imagick and Ghostscript are both in use. WordPress credits pwn.ai. GitHub advisory GHSA-8vr3-7mxf-gx8w scores it 8.8 (CVSS 3.0). Fixed in 7.0.4, with backports through the 4.7 branch (6.9.7, 6.8.8, and the matching older branch builds). No exploitation claim on the WordPress or GitHub notices.
- Product
- WordPress core
- Versions
- 7.0.0-7.0.3, and older branches back through 4.7 before the matching backport
- CVSS
- (CVSS 3.0, GitHub advisory)
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- 7.0.4, or the backport for the branch you run (6.9.7, 6.8.8, through 4.7.35)
Primary: WordPress 7.0.4 release · Vendor: GHSA-8vr3-7mxf-gx8w · CVE: CVE-2026-65640
