securityonline.info 8/13/2026, 9:58:34 AM · external

WordPress flaw CVE-2026-65640 lets authors run code remotely

WordPress flaw CVE-2026-65640 lets authors run code remotely
CyberSIXT Evidence Panel
Primary Source wordpress.org
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability (CVE-2026-65640) affecting WordPress versions 4.7.0 to 7.0.3 has been identified and patched in version 7.0.4. This flaw, which allows authenticated remote code execution via the Imagick and Ghostscript libraries, poses a significant risk, particularly for sites with Author-level accounts. Users are advised to update immediately to reduce exposure risk. Though no active exploitation has been reported, the vulnerability's potential for abuse remains a concern as many sites allow multiple authors.

View Primary Source Via securityonline.info

Article by CyberSIXT