Skip to content

CVE-2026-65640

WordPress remote code execution via PostScript file upload by Author-level users (CVE-2026-65640)

High 8.8 Vendor: WordPress Published

CVE-2026-65640: WordPress before 7.0.4 has a high-severity remote code execution flaw. An Author-level user can upload a malicious PostScript file when Imagick and Ghostscript are enabled. Update to 7.0.4 or the backported release for your branch.

What happened

WordPress's advisory describes a remote code execution vulnerability reached through a malicious PostScript file upload. The attacker must be authenticated at Author level or higher, a role that has the upload_files capability, and the server must use Imagick and Ghostscript to process images. No user interaction beyond the upload is required.

The CVSS 3.0 score is 8.8, high severity, with a network attack vector, low privileges, no user interaction and high impact on confidentiality, integrity and availability. The flaw is classified as unrestricted file upload, CWE-434. WordPress has not said that the vulnerability is being exploited in the wild, and there is no KEV entry for this CVE.

Who is affected

All versions of WordPress before 7.0.4 are affected. The issue matters for sites that allow Author-level or higher users to upload files and that have Imagick and Ghostscript active on the server; deployments lacking either prerequisite are not exposed through this path. WordPress is a public-facing content management system, often with many content roles and media uploads.

WordPress has backported the fix to all maintenance branches back to 4.7. The specific fixed releases are listed below.

What to do now

  1. Confirm your WordPress version and whether Imagick and Ghostscript are in use.
  2. Update to WordPress 7.0.4, or, if you are on an older branch, apply the backported release for that branch: 4.7.35, 4.8.30, 4.9.31, 5.0.27, 5.1.24, 5.2.26, 5.3.23, 5.4.21, 5.5.20, 5.6.19, 5.7.17, 5.8.15, 5.9.16, 6.0.14, 6.1.12, 6.2.11, 6.3.10, 6.4.10, 6.5.10, 6.6.7, 6.7.7, 6.8.8, 6.9.7, 7.0.4.
  3. No workaround has been published by WordPress. Until the update is applied, review which users hold the upload_files capability and whether they still need it.

How to detect it

The advisory does not publish indicators of compromise. To establish exposure, confirm that Imagick and Ghostscript are active on the server and audit the accounts that have the upload_files capability at Author level or higher.

Beyond the patch

Author-level access is easier to obtain than administrator access, so this is not only a patch problem but also a detection and hardening problem. Managed Detection & Response (MDR) is the right layer for detecting the code execution and account misuse that follow such an upload. If you need to verify upload handling and role separation ahead of an incident, Implementation & Assessment Services can test and harden the WordPress installation.

Affected and fixed versions

ProductAffectedFixed in
WordPress– < 7.0.47.0.4
.8.30, 4.9.31, 5.0.27, 5.1.24, 5.2.26, 5.3.23, 5.4.21, 5.5.20, 5.6.19, 5.7.17, 5.8.15, 5.9.16, 6.0.14, 6.1.12, 6.2.11, 6.3.10, 6.4.10, 6.5.10, 6.6.7, 6.7.7, 6.8.8, 6.9.7, 7.0.4

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.