๐Ÿ” CVE Alert

CVE-2026-65640

HIGH 8.8
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.

CWE CWE-434
Vendor wordpress
Product wordpress
Ecosystems
Industries
WebMedia
Published Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for wordpress wordpress

Be the first to know when new high vulnerabilities affecting wordpress wordpress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Versions

WordPress / WordPress
0 < 7.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordpress.org: https://wordpress.org/news/2026/08/wordpress-7-0-4-release/

Credits

Pwn.ai