CVE-2026-65640 is an authenticated remote code execution vulnerability in WordPress affecting sites that use the Imagick extension together with Ghostscript for image processing. The flaw allows an Author-level or higher user to upload a crafted file that bypasses expected file-type validation and is later processed by WordPress through WP_Image_Editor_Imagick::load(). The underlying issue is that some WordPress upload paths relied on filename extensions or skipped full content inspection, while ImageMagick identifies files by actual content and can delegate PostScript, EPS, and PDF handling to Ghostscript. As a result, an attacker could supply a file disguised as an image but containing PostScript, EPS, or malformed PDF content, causing Imagick and Ghostscript to process attacker-controlled data and leading to code execution on the server. The fix rewrites file inspection in WP_Image_Editor_Imagick::load() to validate actual content, reject dangerous signatures and compressed formats, and prevent abuse of format-prefix filename tricks.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authenticated remote code execution vulnerability in WordPress media processing where crafted uploads can bypass consistent content validation and reach the Imagick/ImageMagick/Ghostscript chain, allowing attacker-controlled PostScript-family content to be interpreted and potentially executed.
A remote code execution vulnerability in WordPress involving image processing via the Imagick extension and Ghostscript, where crafted uploads can bypass extension-based checks and trigger dangerous file handling.
An authenticated Author+ remote code execution vulnerability in WordPress, exploitable via malicious file upload on sites that use Imagick and Ghostscript.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.