WordPress has released fixes for CVE-2026-65640, a high-severity flaw that could let authenticated attackers execute arbitrary code through malicious PostScript file uploads. The issue affects installations using Imagick and Ghostscript, and WordPress 7.0.4 plus backports to older branches now block the vulnerable file handling path. #WordPress #CVE-2026-65640 #Imagick #Ghostscript
Keypoints
- WordPress patched CVE-2026-65640, rated 8.8 on the CVSS scale.
- Attackers with Author-level access can trigger remote code execution through crafted uploads.
- The flaw affects sites using Imagick and Ghostscript.
- A PNG file containing embedded PostScript can be used to exploit the issue.
- WordPress 7.0.4 and backported fixes now prevent PostScript execution through uploads.
Read More: https://www.securityweek.com/wordpress-7-0-4-patches-remote-code-execution-vulnerability/