WordPress 7.0.4 Patches Remote Code Execution Vulnerability
WordPress versions prior to 7.0.4 and backported to 4.7 contain a remote code execution vulnerability exploitable by authenticated users with Author-level or higher permissions via malicious PostScript files embedded in image uploads. The flaw arises from how WordPress, through the Imagick extension, processes uploaded files: WordPress checks file extensions while ImageMagick inspects file content and invokes Ghostscript to render PostScript code, enabling execution of arbitrary code. The vulnerability is fixed in WordPress 7.0.4 and backported to all branches back to 4.7 by adding content checks before passing files to Imagick, preventing PostScript execution.
AI Analysis
Technical Summary
CVE-2026-65640 is a remote code execution vulnerability in WordPress affecting installations that use the Imagick PHP extension and Ghostscript. Authenticated attackers with Author-level or higher permissions can exploit this by uploading files with a benign extension (e.g., PNG) containing embedded PostScript code. WordPress previously relied on file extensions to determine processing, while ImageMagick inspects file content and calls Ghostscript to render PostScript, allowing execution of arbitrary code. The vulnerability is mitigated by WordPress 7.0.4, which modifies the load() function to verify file contents before passing them to Imagick, blocking PostScript execution and preventing filename manipulation to invoke Ghostscript.
Potential Impact
Successful exploitation allows authenticated users with Author-level or higher permissions to execute arbitrary code remotely on the server via malicious image uploads containing embedded PostScript. This could lead to full system compromise depending on server configuration and privileges of the WordPress process. The vulnerability affects WordPress sites using Imagick and Ghostscript and having file upload capabilities for such users.
Mitigation Recommendations
WordPress 7.0.4 includes an official fix that addresses this vulnerability by adding content checks before passing files to Imagick, preventing PostScript execution. The fix has been backported to all supported branches back to version 4.7. Site administrators should upgrade to WordPress 7.0.4 or later, or apply the backported patches if running older supported versions. No additional mitigation is required once patched.
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
Description
WordPress versions prior to 7.0.4 and backported to 4.7 contain a remote code execution vulnerability exploitable by authenticated users with Author-level or higher permissions via malicious PostScript files embedded in image uploads. The flaw arises from how WordPress, through the Imagick extension, processes uploaded files: WordPress checks file extensions while ImageMagick inspects file content and invokes Ghostscript to render PostScript code, enabling execution of arbitrary code. The vulnerability is fixed in WordPress 7.0.4 and backported to all branches back to 4.7 by adding content checks before passing files to Imagick, preventing PostScript execution.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-65640 is a remote code execution vulnerability in WordPress affecting installations that use the Imagick PHP extension and Ghostscript. Authenticated attackers with Author-level or higher permissions can exploit this by uploading files with a benign extension (e.g., PNG) containing embedded PostScript code. WordPress previously relied on file extensions to determine processing, while ImageMagick inspects file content and calls Ghostscript to render PostScript, allowing execution of arbitrary code. The vulnerability is mitigated by WordPress 7.0.4, which modifies the load() function to verify file contents before passing them to Imagick, blocking PostScript execution and preventing filename manipulation to invoke Ghostscript.
Potential Impact
Successful exploitation allows authenticated users with Author-level or higher permissions to execute arbitrary code remotely on the server via malicious image uploads containing embedded PostScript. This could lead to full system compromise depending on server configuration and privileges of the WordPress process. The vulnerability affects WordPress sites using Imagick and Ghostscript and having file upload capabilities for such users.
Mitigation Recommendations
WordPress 7.0.4 includes an official fix that addresses this vulnerability by adding content checks before passing files to Imagick, preventing PostScript execution. The fix has been backported to all supported branches back to version 4.7. Site administrators should upgrade to WordPress 7.0.4 or later, or apply the backported patches if running older supported versions. No additional mitigation is required once patched.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/wordpress-7-0-4-patches-remote-code-execution-vulnerability/","fetched":true,"fetchedAt":"2026-08-13T12:56:13.341Z","wordCount":992}
Threat ID: 6a7dbeedbf8831d539340a56
Added to database: 08/13/2026, 12:56:13 UTC
Last enriched: 08/13/2026, 12:56:25 UTC
Last updated: 08/13/2026, 16:55:57 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.