DIRAS TAKE
Urgent: public exploit code is available, so update immediately to 7.0.4 or apply mitigations; the availability of exploit code makes exposure of sites with upload-capable accounts a high-risk vector.
What is CVE-2026-65640?
An authenticated user with the upload_files capability can upload a crafted PostScript file that leads to remote code execution on WordPress installations that use Imagick and Ghostscript. CVE-2026-65640 affects the 7.x branch before 7.0.4; an attacker needs an account with upload privileges (Author or higher) and the site must process the file with Imagick/Ghostscript. No user interaction beyond the authenticated upload is required. The weakness is classified as CWE-434 (Unrestricted File Upload).
Vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of WordPress WordPress are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | before 7.0.4 | 7.0.4 |
Is CVE-2026-65640 being exploited?
Public exploit code is available.
How to fix CVE-2026-65640
- Apply the vendor fix by updating WordPress 7.x to 7.0.4.
- Restrict which roles have the upload_files capability and review user accounts for unnecessary upload privileges.
- Disable or restrict use of Imagick/Ghostscript on servers that process untrusted uploads where feasible.
- Monitor upload and process logs for suspicious PostScript or image conversion activity and unusual process execution.
Frequently asked questions
Is CVE-2026-65640 being actively exploited?
Public exploit code is available for CVE-2026-65640.
Which WordPress versions are affected by CVE-2026-65640?
The 7.x branch before version 7.0.4 is listed as affected; 7.0.4 contains the fix for this issue.
Is there a patch for CVE-2026-65640?
Yes. WordPress 7.0.4 is listed as the fixed version for the affected 7.x branch.
Does CVE-2026-65640 require authentication?
Yes. An attacker needs an account with the upload_files capability (typically Author or higher) and the site must process uploads with Imagick and Ghostscript.
References
- nvd.nist.gov/vuln/detail/CVE-2026-65640
- cve.org/CVERecord?id=CVE-2026-65640
- wordpress.org/news/2026/08/wordpress-7-0-4-release
- All WordPress CVEs on CVE Radar
- CVEs published in September 2026