• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-65640: authenticated remote code execution in WordPress WordPress

An authenticated user with the upload_files capability can upload a crafted PostScript file that leads to remote code execution on WordPress installations that use Imagick and Ghostscript. CVE-2026-65640 affects the 7.x branch before 7.0.4; an attacker needs an account with upload privileges (Author or higher) and the site must process the file with Imagick/Ghostscript. No user interaction beyond the authenticated upload is required.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.0
8.8HIGH
EPSS
0.00796
CWE
CWE-434
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code is available, so update immediately to 7.0.4 or apply mitigations; the availability of exploit code makes exposure of sites with upload-capable accounts a high-risk vector.

What is CVE-2026-65640?

An authenticated user with the upload_files capability can upload a crafted PostScript file that leads to remote code execution on WordPress installations that use Imagick and Ghostscript. CVE-2026-65640 affects the 7.x branch before 7.0.4; an attacker needs an account with upload privileges (Author or higher) and the site must process the file with Imagick/Ghostscript. No user interaction beyond the authenticated upload is required. The weakness is classified as CWE-434 (Unrestricted File Upload).

Vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of WordPress WordPress are affected?

BRANCHAFFECTEDFIXED
7.xbefore 7.0.47.0.4

Is CVE-2026-65640 being exploited?

Public exploit code is available.

How to fix CVE-2026-65640

  1. Apply the vendor fix by updating WordPress 7.x to 7.0.4.
  2. Restrict which roles have the upload_files capability and review user accounts for unnecessary upload privileges.
  3. Disable or restrict use of Imagick/Ghostscript on servers that process untrusted uploads where feasible.
  4. Monitor upload and process logs for suspicious PostScript or image conversion activity and unusual process execution.

Frequently asked questions

Is CVE-2026-65640 being actively exploited?

Public exploit code is available for CVE-2026-65640.

Which WordPress versions are affected by CVE-2026-65640?

The 7.x branch before version 7.0.4 is listed as affected; 7.0.4 contains the fix for this issue.

Is there a patch for CVE-2026-65640?

Yes. WordPress 7.0.4 is listed as the fixed version for the affected 7.x branch.

Does CVE-2026-65640 require authentication?

Yes. An attacker needs an account with the upload_files capability (typically Author or higher) and the site must process uploads with Imagick and Ghostscript.

References