WordPress patches authenticated remote code execution flaw CVE-2026-65640 in version 7.0.4

WordPress released version 7.0.4 to fix a high-severity bug that could let a logged-in contributor or author run malicious code on affected sites by uploading a booby-trapped image file. The flaw, CVE-2026-65640 (CVSS 8.8), affects WordPress installations using Imagick and Ghostscript, where crafted PNG files containing PostScript could trigger code execution. WordPress says the fix was also backported to supported branches as far back as 4.7.
Why it matters: Sites with multiple authors, contributors, membership users, or loosely controlled uploads are at realistic risk and should update promptly. Administrators should patch WordPress, review who has upload rights, and pay special attention to deployments using Imagick and Ghostscript.

Sources

WordPress 7.0.4 Patches Remote Code Execution Vulnerability
Ionut Arghire 2026.08.13 100% relevant
This article establishes a distinct new story about WordPress's release of 7.0.4 to fix CVE-2026-65640; no existing tracked story covers this specific vulnerability and patch event.
← Back to all stories