PT-2026-71974 · WordPress+2 · Wordpress+2

·

CVE-2026-65640

·

Published

2026-08-14

·

Updated

2026-08-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 7.0.4
Description An authenticated user with Author level privileges or higher can achieve remote code execution by uploading a malicious Postscript file. This issue occurs when the server utilizes Imagick and Ghostscript and the user possesses the upload files capability.
Recommendations Update to version 7.0.4 or the latest patched version for your specific branch.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-WORDPRESS-2026-65640
BIT-WORDPRESS-MULTISITE-2026-65640
CVE-2026-65640

Affected Products

Ghostscript
Imagick
Wordpress