
WordPress released version 7.0.4 to fix a critical remote code execution vulnerability, tracked as CVE-2026-65640, that allowed attackers to execute code via malicious file uploads.
The flaw, disclosed by pwn.ai, exploited the Imagick extension's reliance on Ghostscript to process files, enabling authenticated Author-level users to bypass security checks.
Site administrators are urged to update immediately to the new version, which includes commit 7daaa50 to block malicious PostScript and EPS signatures.