Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Subsea tie-back development to US Gulf oil & gas asset is a go

    August 13, 2026

    American Oversight Sues for Records on Trump Administration’s Disruption of Medical Care for People in ICE, CBP Custody

    August 13, 2026

    The Guardian view on A-level and T-level results: a boost to the nation’s confidence | Editorial

    August 13, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Subsea tie-back development to US Gulf oil & gas asset is a go
    • American Oversight Sues for Records on Trump Administration’s Disruption of Medical Care for People in ICE, CBP Custody
    • The Guardian view on A-level and T-level results: a boost to the nation’s confidence | Editorial
    • Trump Uses Deceptive Chart in False Inflation Boast
    • Government could pay higher rents to spread asylum accommodation across UK | Immigration and asylum
    • Person fined for using foghorn to wake sleeping polar bear
    • After Supreme Court Losses, Trump Keeps Pushing
    • Nearly 14,000 crypto holders face security risk after data breach
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 13
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    WordPress 7.0.4 Patches Remote Code Execution Vulnerability

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 13, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    WordPress on Wednesday announced patches for a high-severity vulnerability that allows authenticated attackers to execute arbitrary code remotely.

    Tracked as CVE-2026-65640 (CVSS score of 8.8), the security defect can be exploited by attackers with Author-level user or higher permissions via malicious Postscript file uploads.

    According to WordPress’ advisory, the issue affects only installations that use Imagick and Ghostscript, as it was discovered in Ghostscript’s handling of certain embedded files. Successful exploitation requires that an attacker has file upload rights.

    “WordPress version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches, the fix has been backported to all branches back to 4.7,” the web content management system’s maintainers announced.

    The vulnerability resides in how ImageMagick (through the Imagick extension) and WordPress handle various types of files: ImageMagick looks at the contents, while WordPress looks at the file extension, vulnerability management firm Patchstack explains.

    While WordPress passes an uploaded file to ImageMagick based on its extension, ImageMagick looks at the content and, if it detects PostScript inside, calls Ghostscript to render it.

    Advertisement. Scroll to continue reading.

    This allows an attacker to upload a PNG file containing PostScript, which will be executed in Ghostscript as a PostScript program. While WordPress does contain a function that performs content checks, some upload methods do not, opening the door for exploitation, Patchstack says.

    WordPress addressed the security defect by modifying the load() function to check the file’s contents before passing it to Imagick, preventing PostScript execution. The fix also prevents attackers from using filenames to manipulate Imagick into using Ghostscript.

    “If you run a multi-author publication, a membership site, a client site with contributors, or anything with open or loosely managed registration, […] an Author uploading a booby-trapped ‘image’ is a genuinely realistic threat, not a theoretical one,” Patchstack notes.

    Related: Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

    Related: Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

    Related: Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

    Related: SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

    7.0.4 Code Execution Patches remote Vulnerability WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Adobe Commerce Bug Targeted Immediately After Disclosure

    Cybersecurity M&A Roundup: 21 Deals Announced in July 2026

    Poland detains Russian for ‘execution’ plot in Warsaw, Tusk says

    DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

    Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

    Venture Firm Team8 Secures Additional $365 Million

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Subsea tie-back development to US Gulf oil & gas asset is a go

    August 13, 2026

    American Oversight Sues for Records on Trump Administration’s Disruption of Medical Care for People in ICE, CBP Custody

    August 13, 2026

    The Guardian view on A-level and T-level results: a boost to the nation’s confidence | Editorial

    August 13, 2026

    Trump Uses Deceptive Chart in False Inflation Boast

    August 13, 2026
    Latest Posts

    Evacuated villagers in Cairngorms allowed home after wildfire threat lifts | Wildfires

    July 25, 2026

    The Fraternal Order Of Police Supports The Clarity Act.

    July 25, 2026

    How Synthetic Identity Fraud is Coming for Machine Identities

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subsea tie-back development to US Gulf oil & gas asset is a go

    August 13, 2026

    American Oversight Sues for Records on Trump Administration’s Disruption of Medical Care for People in ICE, CBP Custody

    August 13, 2026

    The Guardian view on A-level and T-level results: a boost to the nation’s confidence | Editorial

    August 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.