www.securityweek.com 8/13/2026, 1:21:08 PM · external

WordPress patches CVE-2026-65640 after remote code flaw found

WordPress patches CVE-2026-65640 after remote code flaw found
Developing story malware 2 articles tracked
WordPress patches CVE-2026-65640 remote code execution flaw
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

WORDPRESS has released a patch for a high-severity vulnerability (CVE-2026-65640) that allows authenticated attackers to execute arbitrary code remotely, with a CVSS score of 8.8. This vulnerability, affecting installations using Imagick and Ghostscript, can be exploited by attackers with author-level permissions through malicious Postscript file uploads.

The recent update, version 7.0.4, addresses this issue by modifying the load() function to verify file contents before processing them, thereby preventing PostScript execution through uploaded files. This vulnerability poses a threat particularly for multi-author websites, making it crucial for users to update their installations.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline