WordPress released 7.0.4 as an emergency security update to fix an authenticated remote code execution flaw affecting sites that use Imagick with Ghostscript for media processing. The vulnerability, tracked as CVE-2026-65640 and GHSA-8vr3-7mxf-gx8w, allows users with Author-level or higher privileges to upload a crafted file and trigger code execution during image handling, prompting WordPress to urge site owners to update immediately.
Reports indicate the bug stemmed from a mismatch between WordPress file-type validation and how ImageMagick identifies content, allowing disguised PostScript, EPS, or malformed PDF/polyglot payloads to be processed as seemingly benign images such as PNG files. WordPress said the issue was responsibly reported by pwn.ai and patched by tightening inspection in WP_Image_Editor_Imagick::load(), blocking dangerous signatures and validating filenames and format prefixes; the fix is also being backported to the 4.7 branch and included in 7.1 RC3.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
A new CVE record was received for CVE-2026-65640, formally describing the WordPress authenticated remote code execution flaw involving malicious PostScript uploads processed through Imagick and Ghostscript. The entry lists affected versions earlier than 7.0.4 and includes CVSS v3 scoring and CWE-434 classification.
CSIRT Panamá published an alert on CVE-2026-65640, warning that the authenticated WordPress Imagick/Ghostscript RCE flaw was being actively exploited in the wild. The advisory identified affected versions as WordPress 4.7.0 through 7.0.3 and urged immediate upgrades to 7.0.4 or later.
Alongside the 7.0.4 release, WordPress said the security fixes were being backported through the 4.7 branch and into the 7.1 RC3 release. This extended the remediation beyond the main current release line.
WordPress released version 7.0.4 as a security update to fix the authenticated Author+ remote code execution issue involving crafted uploads processed by Imagick and Ghostscript. WordPress advised administrators to update immediately, and the fix includes changes to file inspection logic in WP_Image_Editor_Imagick::load().
Researchers at pwn.ai responsibly reported an authenticated remote code execution vulnerability in WordPress affecting Author+ users via malicious file uploads on sites using Imagick and Ghostscript. The flaw is tracked as CVE-2026-65640 and GHSA-8vr3-7mxf-gx8w.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecyberveille.ch
Open sourcecyberveille.ch
Open sourcesecurityweek.com
Open sourcethecybersecguru.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcecert.pa
Open sourcewordpress.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.