CVE Tools
Back to feed
Patch released WordPress rce web-app

WordPress 7.0.4 Patches Remote Code Execution Vulnerability

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

WordPress has released version 7.0.4 to address a high-severity remote code execution vulnerability identified as CVE-2026-65640. This defect, which carries a CVSS score of 8.8, permits attackers with Author-level or higher privileges to execute arbitrary code by uploading malicious Postscript files disguised as images. The issue specifically impacts installations utilizing Imagick and Ghostscript, where a mismatch between WordPress' reliance on file extensions and ImageMagick's content-based processing allows for unintended script execution. While the fix is included in version 7.0.4, maintainers have backported the patch to all supported branches extending back to version 4.7.