WORDPRESS has released a patch for a high-severity vulnerability (CVE-2026-65640) that allows authenticated attackers to execute arbitrary code remotely, with a CVSS score of 8.8. This vulnerability, affecting installations using Imagick and Ghostscript, can be exploited by attackers with author-level permissions through malicious Postscript file uploads.
The recent update, version 7.0.4, addresses this issue by modifying the load() function to verify file contents before processing them, thereby preventing PostScript execution through uploaded files. This vulnerability poses a threat particularly for multi-author websites, making it crucial for users to update their installations.