FR
live
High CVSS 8.8

CVE-2026-65640

NVD analysis in progress

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.

What this means

Exposure
Exploitable remotely over the network, with an ordinary user account and with no action from the victim.
Impact
An attacker can read sensitive data, modify or destroy data and take the service offline.
Weakness
Upload accepts a dangerous file type, often one the server will execute.
Likelihood
Its EPSS score puts short-term exploitation in a middle band: neither negligible nor imminent.

What to doFold into the next patch cycle.

Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.

Published
17 August 2026
CVSS
8.8 (v3.0) CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.95% probability of exploitation within 30 days · above 79% of all CVEs
Weakness
CWE-434
Sources
nvd
References

Type at least two characters.

navigate open esc dismiss