A critical vulnerability (CVE-2026-65640) affecting WordPress versions 4.7.0 to 7.0.3 has been identified and patched in version 7.0.4. This flaw, which allows authenticated remote code execution via the Imagick and Ghostscript libraries, poses a significant risk, particularly for sites with Author-level accounts. Users are advised to update immediately to reduce exposure risk. Though no active exploitation has been reported, the vulnerability's potential for abuse remains a concern as many sites allow multiple authors.
WordPress flaw CVE-2026-65640 lets authors run code remotely
CyberSIXT Evidence Panel
Article by CyberSIXT