news.mlab.sh
Back to the feed
vulnerability

WordPress 7.0.4 Patches Remote Code Execution Vulnerability

High
Summary

WordPress has released version 7.0.4 to address a high-severity remote code execution vulnerability. This flaw, tracked as CVE-2026-65640, allows authenticated attackers to execute code by uploading malicious PostScript files through image uploads, primarily affecting WordPress installations utilizing Imagick and Ghostscript.

Read the full article at SecurityWeek

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.