Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4152 articles · 221979 vulns · 36/41 feeds (7d)
← Back to list
8.8
CVE-2026-65640PATCHED
wordpress · wordpress

CVE-2026-65640: WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level

Description

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.

Affected Products

VendorProductVersions
wordpresswordpress0

References

  • https://wordpress.org/news/2026/08/wordpress-7-0-4-release/

Related News (4 articles)

Tier C
VulDB37d ago
CVE-2026-65640 | WordPress up to 7.0.3 Postscript unrestricted upload
→ No new info (linked only)
Tier D
SecurityWeek42d ago
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
→ No new info (linked only)
Tier B
BSI Advisories42d ago
[NEU] [hoch] WordPress: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier B
CERT-FR42d ago
Vulnérabilité dans WordPress (13 août 2026)
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.8 HIGH
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
7.0.4
CWECWE-434
PublishedAug 17, 2026
Trending Score1
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-87902EXPKEV
CVE-2026-87902: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.ph
Trending: 136
CRITICALCVE-2026-63030EXPKEV
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
Trending: 4
MEDIUMCVE-2026-60137EXPKEV
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
Trending: 3
NONECVE-2026-64638
CVE-2026-64638: WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
Trending: 1
CRITICALCVE-2026-6382EXP
Multiple elFinder Plugins - Authenticated OS Command Injection

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 17, 2026
Discovered by ZDM
Aug 17, 2026
Patch Available
Aug 18, 2026