WordPress 7.0.4 Patches Remote Code Execution Vulnerability
PatchWordPressOur summary
WordPress has released version 7.0.4 to address a high-severity remote code execution vulnerability identified as CVE-2026-65640. This defect, which carries a CVSS score of 8.8, permits attackers with Author-level or higher privileges to execute arbitrary code by uploading malicious Postscript files disguised as images. The issue specifically impacts installations utilizing Imagick and Ghostscript, where a mismatch between WordPress' reliance on file extensions and ImageMagick's content-based processing allows for unintended script execution. While the fix is included in version 7.0.4, maintainers have backported the patch to all supported branches extending back to version 4.7.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.