Patch released WordPress rce web-app
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
CVE Tools coverage
WordPress has released version 7.0.4 to address a high-severity remote code execution vulnerability identified as CVE-2026-65640. This defect, which carries a CVSS score of 8.8, permits attackers with Author-level or higher privileges to execute arbitrary code by uploading malicious Postscript files disguised as images. The issue specifically impacts installations utilizing Imagick and Ghostscript, where a mismatch between WordPress' reliance on file extensions and ImageMagick's content-based processing allows for unintended script execution. While the fix is included in version 7.0.4, maintainers have backported the patch to all supported branches extending back to version 4.7.