High severity8.8NVD Advisory· Published Aug 17, 2026
CVE-2026-65640
CVE-2026-65640
Description
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher.
Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the upload_files capability
This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
5- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and MoreThe Hacker News · Aug 17, 2026
- Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 StoriesCyber Security News · Aug 16, 2026
- WordPress 7.0.4 Patches Remote Code Execution VulnerabilitySecurityWeek · Aug 13, 2026
- Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG FileCyber Security News · Aug 13, 2026
- WordPress 7.0.4 ReleaseWordPress Core Security · Aug 12, 2026