PT-2026-71974 · WordPress+2 · Wordpress+2
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WordPress versions prior to 7.0.4
Description
An authenticated user with Author level privileges or higher can achieve remote code execution by uploading a malicious Postscript file. This issue occurs when the server utilizes Imagick and Ghostscript and the user possesses the
upload files capability.Recommendations
Update to version 7.0.4 or the latest patched version for your specific branch.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghostscript
Imagick
Wordpress